An efficient false alarm reduction approach in HTTP-based botnet detection

In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, use...

Full description

Bibliographic Details
Published in:IEEE Symposium on Computers and Informatics, ISCI 2013
Main Author: Eslahi M.; Hashim H.; Tahir N.M.
Format: Conference paper
Language:English
Published: IEEE Computer Society 2013
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5
id 2-s2.0-84886463156
spelling 2-s2.0-84886463156
Eslahi M.; Hashim H.; Tahir N.M.
An efficient false alarm reduction approach in HTTP-based botnet detection
2013
IEEE Symposium on Computers and Informatics, ISCI 2013


10.1109/ISCI.2013.6612403
https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5
In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, uses the standard HTTP protocol to impersonate normal web traffic and bypass the current network security systems (e.g. firewalls). Besides, HTTP protocol is commonly used by normal applications and services on the Internet, thus detection of the HTTP botnets with a low rate of false alarms (e.g. false negative and false positive) has become a notable challenge. In this paper, we review the current studies on HTTP-based botnet detection in addition to their shortcomings. We also propose a detection approach to improve the HTTP-based botnet detection regarding the rate of false alarms and the detection of HTTP bots with random patterns. The testing result shows that the proposed method is able to reduce the false alarm rates in HTTP-based botnet detection successfully. © 2013 IEEE.
IEEE Computer Society

English
Conference paper

author Eslahi M.; Hashim H.; Tahir N.M.
spellingShingle Eslahi M.; Hashim H.; Tahir N.M.
An efficient false alarm reduction approach in HTTP-based botnet detection
author_facet Eslahi M.; Hashim H.; Tahir N.M.
author_sort Eslahi M.; Hashim H.; Tahir N.M.
title An efficient false alarm reduction approach in HTTP-based botnet detection
title_short An efficient false alarm reduction approach in HTTP-based botnet detection
title_full An efficient false alarm reduction approach in HTTP-based botnet detection
title_fullStr An efficient false alarm reduction approach in HTTP-based botnet detection
title_full_unstemmed An efficient false alarm reduction approach in HTTP-based botnet detection
title_sort An efficient false alarm reduction approach in HTTP-based botnet detection
publishDate 2013
container_title IEEE Symposium on Computers and Informatics, ISCI 2013
container_volume
container_issue
doi_str_mv 10.1109/ISCI.2013.6612403
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5
description In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, uses the standard HTTP protocol to impersonate normal web traffic and bypass the current network security systems (e.g. firewalls). Besides, HTTP protocol is commonly used by normal applications and services on the Internet, thus detection of the HTTP botnets with a low rate of false alarms (e.g. false negative and false positive) has become a notable challenge. In this paper, we review the current studies on HTTP-based botnet detection in addition to their shortcomings. We also propose a detection approach to improve the HTTP-based botnet detection regarding the rate of false alarms and the detection of HTTP bots with random patterns. The testing result shows that the proposed method is able to reduce the false alarm rates in HTTP-based botnet detection successfully. © 2013 IEEE.
publisher IEEE Computer Society
issn
language English
format Conference paper
accesstype
record_format scopus
collection Scopus
_version_ 1792585535473057792