AIセキュリティポータル K Program
Comprehensive Botnet Detection by Mitigating Adversarial Attacks, Navigating the Subtleties of Perturbation Distances and Fortifying Predictions with Conformal Layers
Share
Abstract
Botnets are computer networks controlled by malicious actors that present significant cybersecurity challenges. They autonomously infect, propagate, and coordinate to conduct cybercrimes, necessitating robust detection methods. This research addresses the sophisticated adversarial manipulations posed by attackers, aiming to undermine machine learning-based botnet detection systems. We introduce a flow-based detection approach, leveraging machine learning and deep learning algorithms trained on the ISCX and ISOT datasets. The detection algorithms are optimized using the Genetic Algorithm and Particle Swarm Optimization to obtain a baseline detection method. The Carlini & Wagner (C&W) attack and Generative Adversarial Network (GAN) generate deceptive data with subtle perturbations, targeting each feature used for classification while preserving their semantic and syntactic relationships, which ensures that the adversarial samples retain meaningfulness and realism. An in-depth analysis of the required L2 distance from the original sample for the malware sample to misclassify is performed across various iteration checkpoints, showing different levels of misclassification at different L2 distances of the Pertrub sample from the original sample. Our work delves into the vulnerability of various models, examining the transferability of adversarial examples from a Neural Network surrogate model to Tree-based algorithms. Subsequently, models that initially misclassified the perturbed samples are retrained, enhancing their resilience and detection capabilities. In the final phase, a conformal prediction layer is integrated, significantly rejecting incorrect predictions, of 58.20 % in the ISCX dataset and 98.94 % in the ISOT dataset.
Snort - lightweight intrusion detection for networks
M. Roesch
Published: 1999
Performance Comparison of Intrusion Detection Systems and Application of Machine Learning to Snort System
Syed Ali Raza Shah, Biju Issac
Published: 2017.10.13
Random search for hyper-parameter optimization
J. Bergstra, Y. Bengio
Published: 2012
Machine learning for http botnet detection using classifier algorithms
Dollah, R. F. M., Faizal, M., Arif, F., Mas’ud, M. Z., Xin, L. K.
Published: 2018
Adversarial network traffic: Towards evaluating the robustness of deep-learning-based network traffic classification
A. M. Sadeghzadeh, S. Shiravi, R. Jalili
Published: 2021
Evaluating and improving adversarial robustness of machine learning-based network intrusion detectors
D. Han, G. Wang, X. Zhong, J. Chen, H. Yang, Y. Lu, Y. Shi, H. Yin
Published: 2021
Transcending Transcend: Revisiting Malware Classification in the Presence of Concept Drift
Federico Barbero, Feargus Pendlebury, Fabio Pierazzi, Lorenzo Cavallaro
Published: 2020.10.8
An empirical comparison of botnet detection methods
S. Garcia, M. Grill, J. Stiborek, A. Zunino
Published: 2014
Algorithmic Learning in a Random World
V. Vovk, A. Gammerman, G. Shafer
Published: 2005
Effective feature selection for botnet detection based on network flow analysis
Pektaş, A., Acarman, T.
Published: 2017
DI-NIDS: Domain Invariant Network Intrusion Detection System
Siamak Layeghy, Mahsa Baktashmotlagh, Marius Portmann
Published: 2022.10.15
Deep residual convolutional neural Network: An efficient technique for intrusion detection system
Kumar, G., Kumar, R., Kumar, K., Sai, N., Brahmaiah, M.
Published: 2024
Tad: Transfer learning-based multi-adversarial detection of evasion attacks against network intrusion detection systems
I. Debicha, R. Bauwens, T. Debatty, J.-M. Dricot, T. Kenaza, W. Mees
Published: 2023
Adv-Bot: Realistic adversarial botnet attacks against network intrusion detection systems
I. Debicha, B. Cochez, T. Kenaza, T. Debatty, J. M. Dricot, W. Mees
Published: 2023
Untargeted white-box adversarial attack with heuristic defence methods in real-time deep learning based network intrusion detection system
K. Roshan, A. Zafar, S. B. Ul Haque
Published: 2024
RAIDS: Robust autoencoder-based intrusion detection system model against adversarial attacks
A. Sarıkaya, B. G. Kılıç, M. Demirci
Published: 2023
A Novel Deep Learning based Model to Defend Network Intrusion Detection System against Adversarial Attacks
Khushnaseeb Roshan, Aasim Zafar, Shiekh Burhan Ul Haque
Published: 2023.8.1
Wasserstein generative adversarial networks
M. Arjovsky, S. Chintala, L. Bottou
Share