Machine Learning Algorithms on Botnet Traffic
Rob McKay, Brian Pendleton, James Britt, Ben Nakhavanit · 2019
The authors introduce the Bronte machine learning evaluation study for consistent detection of malware, specifically honed for botnets. Machine learning algorithms are already being used to detect malware in dynamic environments. This evaluation utilizes a static measurement approach that could be implemented on edge network devices. It was generated from conversation-based network traffic. This study fully enumerated the network traffic features to allow various machine learning algorithms to build various training sets to deploy against dual test sets. Utilizing the Waikato Environment for Knowledge Analysis (WEKA) datamining and analysis tool, various algorithmic experiments were deployed against the modern and large CICIDS2017 dataset. This evaluation study aimed to push non-IP address features through a series of machine learning classifiers. The study was conducted differently and more methodically than other related studies by using three highly randomized training sets and two test data sets. The test sets were different in that one was a real world based 98.9 benign traffic and one was 50/50 benign to bot traffic. The instance based nearest neighbor and decision tree classifiers ranked highest only using the training sets; but the J48, an expanded ID3 decision tree classifier, clearly produced the highest predictions against both test sets.