Botnet traffic detection using RPCA and Mahalanobis Distance
Eduardo S. C. Vilaca, Thiago Pereira Vieira, Rafael T. de Sousa, João Paulo C. L. da Costa · 2019
The botnet attack method comprises a network of devices infected by malwares. After the infection, they start to be controlled by a botmaster to perform malicious operations. Because the high traffic of packets, it is challenging for network administrators to monitor the logs to detect those attacks. Therefore, this work proposes a semi-supervised machine learning model intending to identify anomalies on network traffic to detect potential attacks in an automated way. The proposed technique is named RPCA-MD, which applies Robust Principal Component Analysis (RPCA) and Mahalanobis Distance.