Intelligent Detection and Analysis Techniques for Botnet Malicious Traffic
Yunxiao Wang, Yansheng Qu, Lin Sang, Bo Cui, Lijuan Xu, Xin Li · 2024
The continuous evolution of botnets has brought significant challenges to network security. Aiming at the limitations of traditional botnet detection methods in the face of new botnets, we propose a feature selection method that integrates information-theoretic entropy value and Principal Component Analysis (PCA) and analyzes the traffic paths and community structure of botnets in-depth through the Weighted Directed Graph Algorithm. The research method includes using entropy value to evaluate the information content of each feature in network traffic data, combined with PCA to assign weights to features for optimizing feature selection; adopting the XGBoost classifier and combining the optimized feature set for model training to achieve accurate detection of malicious traffic in botnets; and proposing a traffic path reconstruction method based on weighted directed graphs to identify the major and minor traffic paths intelligently. Applying this research method to the NF-CSE-CIC-IDS2018-v2 dataset shows that this study’s proposed feature selection method effectively improves botnet detection accuracy. Moreover, the path analysis method based on weighted directed graphs also effectively reveals network traffic’s propagation paths and community structures. The findings of this study not only substantially improve the accuracy and enhance the efficiency of botnet detection but also provide an in-depth understanding of botnets in cybersecurity. They enable us to find better strategies to counter threats, which is of great theoretical value and practical significance.