透過您的圖書館登入
IP:3.17.154.171
  • 學位論文

使用非監督式機器學習之僵屍網路偵測

Botnet Detection Using Unsupervised Machine Learning

指導教授 : 孫宏民
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


This research focuses on botnet detection through implementation of techniques such as traffic analysis, unsupervised machine learning, and similarity analysis between benign traffic data and bot traffic data. In this study, we tested and experimented with different clustering algorithms and recorded their accuracy with our prepared datasets. Later, the best clustering algorithm was used to proceed with the next steps of the methodology such as determination of majority clusters (cluster with most flows), removal of duplicate flows, and calculation of similarity analysis. Results were recorded for the removal of duplicate flows stage, the results indicate how many flows each majority cluster contains and how many duplicate flows were removed from this majority cluster. Next, results for similarity analysis indicate the value of the similarity coefficient for the comparisons between all datasets (bot datasets and benign dataset.) With these results we can conclude and present some concluding heuristics for determining possible bot infection in a certain host.

關鍵字

殭屍網路 偵測 機器學習 演算法 相似度

並列摘要


本研究使用了不同的技術來偵測殭屍網路, 我們使用了網路流量分析, 非監督式學習, 以及分析正常網路與殭屍網路之間的相似性等技術來實踐。 研究中, 我們測試了不同的分群演算法並比較它們的表現, 下一步,我們選擇表現最好的分群演算法,去決定主群體還有移除多餘且相同的網路資料, 並分析其相似度。 藉由計算出的網路相似度結果, 我們設計出了啟發式的方法來偵測殭屍網路

並列關鍵字

Botnet Detection Machine Learning Clustering Similarity

參考文獻


[14] Pijush Barthakur, Manoj Dahal, and Mrinal Kanti Ghose. Clusibothealer: Botnet
[24] Norbert Pohlmanna Christian J. Dietricha, Christian Rossowa. Cocospot: Clustering
[9] Sherif Saad, Issa Traore, Ali A. Ghorbani, Bassam Sayed, David Zhao, Wei Lu, John
[11] David Zhao, Issa Traore, Bassam Sayed, and ... Botnet detection based on traffic
[15] Nicolás García-Pedrajas, Aida de Haro-García, and Javier Pérez-Rodríguez. A scalable

延伸閱讀