Improving Botnet Detection with a Generative Adversarial Network-Based Technique

Shehla Gul, Sobia Arshad, Sanay Muhammad Umar Saeed, Adeel Akram, Bakhtawar Saeed, Muhammad Awais Azam · 2023

The number of internet users has increased rapidly, leading to significant concern for individuals about cyber attacks. These attacks have evolved and have become more complex, posing a challenge to their detection and prevention. Botnets are high-risk cyber-attacks that are constantly emerging and changing with time. Many studies have suggested using Machine Learning (ML) techniques to detect and classify botnetattacks. However, traditional algorithms often miss many attacks or generate false alarms in large-scale network environments with high bandwidth. The scarcity of data about attacks results in imbalanced training sets that can impact the analysis performance of these methods. We propose a Generative Adversarial Networks (GANs) based oversampling technique to address this problem. We use Wasserstein GANs (WGANs) to simulate botnet attacks and create synthetic attack instances that mimic the high-dimensional distribution of botnet attacks. The experiments have been performed on the CICIDS-2017 dataset. After addressing the issue of imbalanced class, we employed several ML classifiers - Random Forest (RF), K-Nearest Neighbor (KNN), Naive Bayes (NB), Support Vector Machine (SVM), Multi-Layer Perceptron (MLP), and Gradient Boosting Decision Trees (GBDT) to detect botnet attacks. We attained the highest accuracy of 99.9% for the GBDT classifier. The outcomes have shown that the suggested method can successfully address the issue of class imbalance, enhance ML models' detection performance, and outperform state-of-the-art techniques.

Read the paper · More papers on PaperTik