Botnet detection in network system through hybrid low variance filter, correlation filter and supervised mining process

Ferry Astika Saputra, Muhammad Fajar Masputra, Iwan Syarif, Kalamullah Ramli

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

To date, malware caused by botnet activities is one of the most serious cybersecurity threats faced by internet communities. Researchers have proposed data-mining-based IDS as an alternative solution to misuse-based IDS and anomaly-based IDS to detect botnet activities. In this paper, we propose a new method that improves IDS performance to detect botnets. Our method combines two statistical methods, namely low variance filter and Pearson correlation filter, in the feature-selection process. To prove our method can increase the performance of a data-mining-based IDS, we use accuracy and computational time as parameters. A benchmark intrusion dataset (ISCX2017) is used to evaluate our work. Thus, our method reduces the number of features to be processed by the IDS from 77 to 15. Although the number of features decreases, it does not significantly change the accuracy. The computational time is decreased from 71 seconds to 5.6 seconds.

Original languageEnglish
Title of host publication2018 13th International Conference on Digital Information Management, ICDIM 2018
EditorsEzendu Ariwa, Pit Pichappan, Pit Pichappan, Wael M El-Medany, Asif Naeem
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages112-117
Number of pages6
ISBN (Electronic)9781538652435
DOIs
Publication statusPublished - 1 Sep 2018
Event13th International Conference on Digital Information Management, ICDIM 2018 - Berlin, Germany
Duration: 24 Sep 201826 Sep 2018

Publication series

Name2018 13th International Conference on Digital Information Management, ICDIM 2018

Conference

Conference13th International Conference on Digital Information Management, ICDIM 2018
CountryGermany
CityBerlin
Period24/09/1826/09/18

Keywords

  • Feature selection
  • Intrusion detection system
  • ISCX2017 datasets
  • Low variance filter
  • Pearson correlation filter
  • Supervised mining

Fingerprint Dive into the research topics of 'Botnet detection in network system through hybrid low variance filter, correlation filter and supervised mining process'. Together they form a unique fingerprint.

Cite this