An efficient false alarm reduction approach in HTTP-based botnet detection
In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, use...
Published in: | IEEE Symposium on Computers and Informatics, ISCI 2013 |
---|---|
Main Author: | |
Format: | Conference paper |
Language: | English |
Published: |
IEEE Computer Society
2013
|
Online Access: | https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5 |
id |
2-s2.0-84886463156 |
---|---|
spelling |
2-s2.0-84886463156 Eslahi M.; Hashim H.; Tahir N.M. An efficient false alarm reduction approach in HTTP-based botnet detection 2013 IEEE Symposium on Computers and Informatics, ISCI 2013 10.1109/ISCI.2013.6612403 https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5 In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, uses the standard HTTP protocol to impersonate normal web traffic and bypass the current network security systems (e.g. firewalls). Besides, HTTP protocol is commonly used by normal applications and services on the Internet, thus detection of the HTTP botnets with a low rate of false alarms (e.g. false negative and false positive) has become a notable challenge. In this paper, we review the current studies on HTTP-based botnet detection in addition to their shortcomings. We also propose a detection approach to improve the HTTP-based botnet detection regarding the rate of false alarms and the detection of HTTP bots with random patterns. The testing result shows that the proposed method is able to reduce the false alarm rates in HTTP-based botnet detection successfully. © 2013 IEEE. IEEE Computer Society English Conference paper |
author |
Eslahi M.; Hashim H.; Tahir N.M. |
spellingShingle |
Eslahi M.; Hashim H.; Tahir N.M. An efficient false alarm reduction approach in HTTP-based botnet detection |
author_facet |
Eslahi M.; Hashim H.; Tahir N.M. |
author_sort |
Eslahi M.; Hashim H.; Tahir N.M. |
title |
An efficient false alarm reduction approach in HTTP-based botnet detection |
title_short |
An efficient false alarm reduction approach in HTTP-based botnet detection |
title_full |
An efficient false alarm reduction approach in HTTP-based botnet detection |
title_fullStr |
An efficient false alarm reduction approach in HTTP-based botnet detection |
title_full_unstemmed |
An efficient false alarm reduction approach in HTTP-based botnet detection |
title_sort |
An efficient false alarm reduction approach in HTTP-based botnet detection |
publishDate |
2013 |
container_title |
IEEE Symposium on Computers and Informatics, ISCI 2013 |
container_volume |
|
container_issue |
|
doi_str_mv |
10.1109/ISCI.2013.6612403 |
url |
https://www.scopus.com/inward/record.uri?eid=2-s2.0-84886463156&doi=10.1109%2fISCI.2013.6612403&partnerID=40&md5=a34d5bcc63bd85818f9231e78556e6c5 |
description |
In recent years, bots and botnets have become one of the most dangerous infrastructure to carry out nearly every type of cyber-attack. Their dynamic and flexible nature along with sophisticated mechanisms makes them difficult to detect. One of the latest generations of botnet, called HTTP-based, uses the standard HTTP protocol to impersonate normal web traffic and bypass the current network security systems (e.g. firewalls). Besides, HTTP protocol is commonly used by normal applications and services on the Internet, thus detection of the HTTP botnets with a low rate of false alarms (e.g. false negative and false positive) has become a notable challenge. In this paper, we review the current studies on HTTP-based botnet detection in addition to their shortcomings. We also propose a detection approach to improve the HTTP-based botnet detection regarding the rate of false alarms and the detection of HTTP bots with random patterns. The testing result shows that the proposed method is able to reduce the false alarm rates in HTTP-based botnet detection successfully. © 2013 IEEE. |
publisher |
IEEE Computer Society |
issn |
|
language |
English |
format |
Conference paper |
accesstype |
|
record_format |
scopus |
collection |
Scopus |
_version_ |
1809677611498995712 |