Botnet Detection by including payload information of packets through machine learning
B Samarendranath, Dinesh Rao B, Mamatha Balachandra, Prathiksha Prathiksha · 2024
Botnets are collections of compromised devices manipulated by malicious entities. To safeguard against their varied and constantly evolving threats, it is essential to have sophisticated detection techniques in place. In this work, we investigate the utilization of machine learning methodologies for identifying botnets using CTU-13, a large repository that contains a wide range of botnet examples. By extracting features from the packet payloads and the header data, we are able to distinguish between botnet and harmless network traffic. We utilize a range of supervised machine learning techniques, including a Convolutional Neural Network (CNN), to identify botnet behavior. With rigorous evaluation, we see the nuanced performance of various machine learning models. In particular, we find that the naive Bayes classifier is very effective in detecting botnets, while CNN shows remarkable accuracy, especially when it is asked to classify botnet data converted to images. We also explore preprocessing techniques that improve the quality of textual data. This helps to improve feature extraction as well as model performance, emphasizing the importance of proper data preparation for cybersecurity analyses. These insights not only shed light on how effective machine learning can be in detecting botnets but also provide actionable recommendations for improving cyber security strategies.