FGT-B Model for Botnet Attack Detection Using Hybrid Analysis with Data Filtering and Aggregation Data Based on Network Traffic Flows
International journal of intelligent engineering and systems · 2024
Cyber-attacks are a serious threat and require proper anticipation.The currently developing attacks use botnets to attack networks with activities such as phishing, identity theft, Distributed Denial of Service (DDoS), spamming, and personal information theft.The development of a botnet detection model is needed to analyze, identify, accurately detect, and anticipate attack activities to reduce the risk of system damage, data theft, and more severe information.Previous studies have introduced botnet attack detection models using anomaly-based, signature, and mining-based approaches.However, the detection results only show the existence of attacks, have less than optimal detection accuracy, and require complex techniques to analyze attacks based on huge network traffic data.In fact, a botnet detection model design is needed to detect accurately and realistically and recognize different types of malware attacks with different characteristics.This paper proposes a botnet attack detection model with a data aggregation approach obtained by extracting attack behavior on frequency analysis, behavior graphs, and activity time on network traffic flows.The proposed research aims to design an accurate botnet attack detection model through a new approach, using data aggregation techniques based on attack characteristic analysis to detect it accurately and precisely.The novelty of the proposed model is the analysis approach with data filtering and aggregation techniques by combining botnet attack characteristics, namely activity frequency, behavior graph, and activity time segmentation on network traffic flow data, to increase accuracy and optimize computational processing.Three different datasets, namely CTU-13, NCC-1, and NCC-2, were used in the experiment and showed that the proposed model obtained high-performance detection in detecting botnet attacks in three different datasets with an average detection accuracy above 92%, precision above 86.72%,recall above 92%, and F1-Score above 88.89%.The best computation time on the NCC dataset was 39.0617 seconds.The proposed model can help network administrators analyze and determine handling steps on the network when a botnet attack occurs.