HTTP-Based Peer-to-Peer Botnet Detection Using a Machine Learning Bagging Classifier
Dabire Christ Fortune, Sawadogo S. Mathurin, Saptadeepa Kalita · 2024
This work presents a leveraging a machine learning bagging classifier, specifically the LightGBM framework, recognized for its efficiency in handling large-scale data. The unique contributions entail the creation of an exhaustive feature set, merging direct flow-based features with hand-engineered statistical features. Notably, the focus remains solely on P2P botnets, excluding features linked to IRC botnets, refining the study's scope. The model construction involved meticulous feature selection using Select-K-Best and Recursive Feature Elimination (RFE) algorithms, resulting in 10 optimal features from an initial pool of 23. Hyper-parameter tuning, specifically adjusting max depth, aimed to enhance model robustness and reduce overfitting. Testing revealed exceptional model performance, boasting 99.90% accuracy, 99.93% precision, 99.95% recall, and a 99.94% F1 score. This demonstrates the efficacy and dependability of the approach in identifying P2P botnets within network traffic. To conclude, the research significantly contributes by furnishing an exhaustive feature set, concentrating exclusively on P2P botnets, and leveraging the LightGBM model for improved efficiency and accuracy. This not only pushes the boundaries of botnet detection but also sets the stage for future research in this domain