Botnet Detection in Distributed Network Using Machine Learning- A Detailed Review
Ruchi Jain, Neelu Nihalani · 2024
Nowadays millions of data breaches occurred, primarily through ransomware and cyber-attacks. Attackers often use botnets, networks of malware-infected devices controlled by a bot-herder, to target organizations. These botnets, formed using victim devices commandeered through emails, spams, etc., enable large-scale attacks like distributed denial-of-service (DDoS). Identifying the bot-herder and the infected network poses a significant challenge for cybersecurity analysts. The evolving structures of botnets necessitate advanced detection methods. Machine learning (ML) has been introduced in cybersecurity to analyze features of these attacks. By training models with data from previous attacks, ML aids in predicting future incidents. Techniques like detecting the DNS of core command and control (CC) servers using AI are becoming widespread. This work reviews state-of-the-art ML-based botnet detection, comparing data under performance parameters like accuracy, precision, and F-1 score, while acknowledging limitations. The future of botnet detection is expected to involve advanced ML techniques, real-time analysis, and a focus on IoT and decentralized networks. Collaborative defense strategies, increased use of behavioral analysis, and adapting to emerging technologies like quantum computing are anticipated to be central to future botnet detection efforts.