An Unsupervised Ensemble Learning Approach for Novelty-based Botnet Detectors

Mehrdad Hajizadeh, Milad Abbaszadeh Jahromi, Thomas Bauschert · 2022

Botnets are categorized as one of the top 15 security threats by the European Union Agency for Cybersecurity (ENISA) in 2020. Thus, various Machine Learning (ML) algorithms have been proposed to fight against bot activities. Meanwhile, attackers constantly update their malware, making it more undetectable. Consequently, many proposed methods fail in detecting Cyber attacks from novel botnets. This paper presents a novel ensemble learning framework in which diverse standalone novelty-based learners are trained with legitimate traffic to detect previously unseen benign and anomalous traffic flows. Then, the predictions of these base learners are fed into an unsupervised neural network-based as an ensemble model to be combined. The results show that our proposed unsupervised ensemble learning framework yields an improved botnet detection performance (F1 Score=(0.9957 ± 0.0000) %) while minimizing false alarms. Also, our framework outperforms any contributing base learner and the baseline ensemble method, i.e., majority voting.

Read the paper · More papers on PaperTik