Comprehensive Intrusion Detection for Investigating Network Traffic and Botnet Attacks

K.Srinivasa Rao, D.Manoz Reddy · 2024

Botnet attacks pose a substantial threat within the Internet of Things (IoT) ecosystem, often beginning with scanning activities and culminating in distributed denial of service (DDoS) assaults. While most existing research focuses on identifying botnet attacks post-compromise and during DDoS execution, many machine learning-based detection models struggle to generalize due to their reliance on specific training datasets. This limitation hampers their performance across diverse attack patterns. To address this issue, we developed a comprehensive dataset that includes 33 types of scanning activities and 60 types of DDoS attacks, supplemented by samples from three publicly available datasets to enhance attack coverage and improve the robustness of machine learning algorithms. Our approach employs a dual-phase machine learning strategy aimed at both preventing and detecting IoT botnet attacks. In the first phase, we deploy a state-of-the-art deep learning model, ResNet-18, to detect scanning activities indicative of potential botnet threats at an early stage. In the second phase, another ResNet-18 model is utilized to identify DDoS attacks, thereby covering the full spectrum of IoT botnet activities. Our proposed dual-phase strategy achieves notable performance metrics, including $98.89 \%$ accuracy, $99.01 \%$ precision, $98.74 \%$ recall, and a $98.87 \%$ F1-score in the prevention and detection of IoT botnet attacks. To verify the effectiveness of our approach, we compared it against three other ResNet-18 models trained on different datasets for scan and DDoS attack detection. Experimental results demonstrate the superior efficiency of our dual-phase approach in mitigating botnet threats.

Read the paper · More papers on PaperTik