Title :
Architecture for Applying Data Mining and Visualization on Network Flow for Botnet Traffic Detection
Author :
Shahrestani, Alireza ; Feily, Maryam ; Ahmad, Rodina ; Ramadass, Sureswaran
Author_Institution :
Fac. of Comput. Sci. & Inf. Technol., Univ. of Malaya (UM), Kuala Lumpur, Malaysia
Abstract :
Botnet is one of the most recent tools used in cyber-crime including distributed denial of service attacks, phishing, spamming, and spying on remote computers. These days, governments, business, and individuals are facing catastrophic damages caused by hackers using malicious botnets. It is a major challenge for cyber-security research community to combat the emerging threat of botnets. Current network intrusion detection methods based on anomaly detection approaches suffer from fairly high error rate and low performance. The proposed flow based botnet detection system tackles these issues by combining data mining and visualization. The anomalous data is passed to several trust models, and the flows are re-evaluated to obtain their trustfulness, which is then aggregated to detect malicious traffic via visualization. The visualized information will be analyzed by human intellectual and conceptual ability to gain useful knowledge about botnet activities for further precaution and validation.
Keywords :
computer crime; data mining; data visualisation; error statistics; unsolicited e-mail; botnet traffic detection; cyber-security; cybercrime; data mining; data visualization; distributed denial of service attacks; error rate; malicious botnets; network flow; network intrusion detection methods; phishing; spamming; Computer architecture; Computer crime; Computer hacking; Computer security; Data mining; Data visualization; Distributed computing; Government; Intrusion detection; Telecommunication traffic; Botnet; Botnet Detection; Data Mining; Visualization;
Conference_Titel :
Computer Technology and Development, 2009. ICCTD '09. International Conference on
Conference_Location :
Kota Kinabalu
Print_ISBN :
978-0-7695-3892-1
DOI :
10.1109/ICCTD.2009.82