Detecting Botnet Victims Through Graph-Based Machine Learning
Kyle Millar, Lachlan Simpson, Adriel Cheng, Hong Gunn Chew, Cheng‐Chew Lim · 2021
Botnets are one of the most devastating cybersecurity threats to modern organisations. A botnet is a distributed network of compromised devices that is leveraged to perform various malicious operations over the internet. The recent proliferation of unabated botnet activity has necessitated the investigation of novel botnet detection strategies. In this paper, we introduce BiSAGE; a graph-based machine learning technique capable of detecting the compromised hosts (bot victims) operating on a network. The advantage of our approach is that a bot victim can be detected not only through its actions but also through the actions of the devices it communicates with; an intrinsic characteristic of botnet activity. We provide an empirical evaluation of BiSAGE on CSE-CIC-IDS2018; a comprehensive dataset for evaluating intrusion detection systems. We show that BiSAGE is able to accurately identify bot victims without requiring any labelled samples of botnet activity.