詳細表示

No 261236
標題(和) Traffic Feature-based Botnet Detection Scheme Emphasizing the Importance of Long Patterns
標題(英) Traffic Feature-based Botnet Detection Scheme Emphasizing the Importance of Long Patterns
研究会名(和) 通信方式
研究会名(英) Communication Systems
開催年月日 2019-07-04
終了年月日 2019-07-05
会議種別コード 5
共催団体名(和)
資料番号 CS2019-18
抄録(和)
抄録(英) The botnet detection is imperative. Among several detection schemes, the promising one uses the communication sequences. The main idea of that scheme is that the communication sequences represent special feature since they are controlled by programs. That sequence is tokenized to truncated sequences by $n$-gram and the numbers of each pattern\'s occurrence are used as a feature vector. However, although the features are normalized by the total number of all patterns\' occurrences, the number of occurrences in larger $n$ are less than those of smaller $n$. That is, regardless of the value of $n$, the previous scheme normalizes it by the total number of all patterns\' occurrences. As a result, normalized long patterns\' features become very small value and are hidden by others. In order to overcome this shortcoming, in this paper, we propose tit. We realize the emphasizing by two ideas. The first idea is normalizing occurrences by the total number of occurrences in each $n$ instead of the total number of all patterns\' occurrences. By doing this, smaller occurrences in larger $n$ are normalized by smaller values and the feature becomes more balanced with larger value. The second idea is giving weights to the normalized features by calculating ranks of the normalized feature. By weighting features according to the ranks, we can get more outstanding features of longer patterns. By the computer simulation with real dataset, we show the effectiveness of our scheme.
収録資料名(和) 電子情報通信学会技術研究報告
収録資料の巻号 Vol.119, No.101
ページ開始 31
ページ終了 35
キーワード(和)
キーワード(英) botnet detection,machine learning,feature emphasizing
本文の言語 ENG
著者(和) 安毅宸
著者(ヨミ) アン イチェン
著者(英) Yichen An
所属機関(和) 慶應義塾大学
所属機関(英) Keio University
著者(和) 春田秀一郎
著者(ヨミ) ハルタ シュウイチロウ
著者(英) Shuichiro Haruta
所属機関(和) 慶應義塾大学
所属機関(英) Keio University
著者(和) 崔相勳
著者(ヨミ) チェ サンフン
著者(英) Sanghun Choi
所属機関(和) 慶應義塾大学
所属機関(英) Keio University
著者(和) 笹瀬巌
著者(ヨミ) ササセ イワオ
著者(英) Iwao Sasase
所属機関(和) 慶應義塾大学
所属機関(英) Keio University

WWW サーバ管理者
E-mail: webmaster@ieice.org