BGP Features and Classification of Internet Worms and Ransomware Attacks

Hardeep Kaur Takhar, Ljiljana Trajković · 2023

Machine learning approaches for detecting anomalies in communication networks heavily depend on the properties of training data. We analyze the impact of data probability distributions on performance of machine learning models developed based on Border Gateway Protocol datasets collected during the worm and ransomware attacks. Feature selection is performed to determine the most important features and identify their best fitting distributions. Experimental results indicate that certain features follow heavy-tailed distributions. Traffic anomalies are then classified based on selected features using the gradient boosting decision tree models suitable for designing real-time and scalable intrusion detection systems.

Read the paper · More papers on PaperTik