Detection and behavioral analysis of botnets using honeynets and classification techniques
Mahesh Banerjee · 2021
Nowadays, botnets are used for carrying out multitude of cyberattacks such as distributed denial of service (DDoS) and phishing attacks and also for generation and distribution of malwares. Botnets provide an army of bots to the attacker, hence amplifying the strength of launching attacks on large number of targets. An instance of botnet attack named Mirai Japanese for “the future” in 2016 almost stalled the Internet on the east coast of the United States. DDoS attack launched by Mirai botnet flooded its target with a bandwidth of 620 Gbps and took down several websites such as GitHub, Twitter, Netflix, and Reddit. Botnets can be detected using honeynets, and their behavior can be analyzed using machine learning classifiers. Honeynets are used for capturing data in the form of network traffic dumps which are used to extract network flow of the traffic. The network flow is used to analyze the behavior of the traffic originating from the hosts; in this case, the hosts are generally botnets. Behavioral analysis is done for finding patterns exhibited by botnets using machine learning classifiers. Machine learning classifiers such as decision tree, logistical regression, support vector machine, and random forest are used for learning the behavior of the traffic belonging to botnet, and later are used for predicting the traffic segments belonging to a botnet from an unseen or testing data.