Malicious Attacks Detection Using Machine Learning

Chakravarma Sai Tejaswi, Yemireddy Chaitanya, Angelin Gladys Jesudoss, Prayla Shyry · 2022 4th International Conference on Inventive Research in Computing Applications (ICIRCA) · 2022

Botnet, which are used for cybercrime, have recently become a powerful threat on the Internet. Using machine learning techniques, the different ways to detect botnet are examined. There are various types of botnet attack, such as DDOS, spamming, fraud, etc., that can be used by malicious users to attack systems. In order to detect such attacks, packet analysis signatures are used and marked as normal or as human attacks. In order to identify if a new request packet is an attack or not, signatures will be applied, and this method requires manual effort and is updated every time a new attack occurs. The author will utilise machine learning algorithms in order to overcome the above problem. Machine learning algorithms will be used to train and create a model, which will then be applied to new request data to detect normal and abnormal actions. Using the KMEANS algorithm, the dataset will be separated into BOT and BENIGN records. This approach will use graph-based features to extract features from the dataset. Data will be sent to a graph, where each address will be represented as a vertex, and edge connections will be made between the source and destination. Edge weights will be calculated based on incoming and outgoing link connections. To determine edge weights, different parameters such as betweenness centrality, incoming edge weight, outgoing edge weight, and alpha_centrality weight are calculated. The results from all these calculations are combined into in-deg, outdeg, in-deg_wt, out_deg_wt, clustering, and alpha_centrality as features. If there are a high number of connections, then the label will read “1” (BOT); if not, then “0” (normal).

Read the paper · More papers on PaperTik