Performance Analysis of Decision Tree C4.5 as a Classification Technique to Conduct Network Forensics for Botnet Activities in Internet of Things

Rizky Tri Wiyono, Niken Dwi Wahyu Cahyani · 2020

The increased devices connected to the internet are underpinning the growth of the Internet of Things (IoT); but many of these devices are inherently insecure, freely exposed on the internet, and allow for a variety of cyberattacks activity. Lately, IoT has been influenced and infected by various botnet activities with intelligence and with different behavior included distributed denial of service (DDoS) attacks, spamming, and phishing. While botnets with such attacks caused serious security risk to the Internet infrastructure for years, there has been no network forensics technique that can classify, identify, and track the behavior of sophisticated botnets to date. In recent years, so there are many studies that have used classification techniques like an algorithm decision tree to train and validate modeling to define these botnet attacks, but they still produced high errors in assist investigating botnet traces. This motivated the development of a new classification techniques algorithm for network forensics based on the identification of network flows and that could track the suspected botnet activity in the infected network. Based on the performance analysis and experimental results, it is found that by combining selection features and classification techniques with decision tree C4.5 and network flow identification effective enough to identify, classify attacks, and assisting trace of botnet activity on the IoT.

Read the paper · More papers on PaperTik