Reducing the False Alarm Rates in Detecting Botnets Using the Combination of K-Nearest Neighbors and Stochastic Gradient Descent Algorithms

Message:
Article Type:
Research/Original Article (دارای رتبه معتبر)
Abstract:
With the increasing expansion of networks connected to the internet, attackers' efforts against these networks have also grown. Therefore, many researchers have proposed solutions to deal with botnets that lead to remote contamination of systems. One of the main problems of existing methods is the high rate of false alarms produced by attack detection systems, including the rate of false positives and false negatives. In the present research, by using machine learning algorithms, these alarm rates were reduced. In the first stage of the proposed solution, the dataset entered a pre-processing stage so that outliers and noise data were identified and discarded. Then, using the K-Nearest Neighbor algorithm, the non-useful features that had no effect in determining the data class were excluded from the dataset. In the next step, the Gradient Descent algorithm was used to accurately detect the class of data and categorize them into normal data or botnet attack. Finally, by performing various tests on the CTU-13 and BoT-IoT datasets in both binary and multi-class modes, the values of the important criteria for evaluating the effectiveness of the botnet attack detection system were obtained. The results showed that in the CTU-13 dataset, in binary and multi-class mode, the false negative rates were 0.01 and 0.04, and the false positive rates were 0.01 and 0.05, respectively; and for the BoT-IoT dataset, in binary and multi-class mode, the false negative rates were 0.02 and 0.05 and the false positive rates were 0.03 and 0.05, respectively. Compared to other existing methods, the proposed method is superior and demonstrates a reduction in the rate of false alarms and improves efficiency.
Language:
Persian
Published:
Pages:
553 to 570
https://magiran.com/p2716989  
دانلود و مطالعه متن این مقاله با یکی از روشهای زیر امکان پذیر است:
اشتراک شخصی
با عضویت و پرداخت آنلاین حق اشتراک یک‌ساله به مبلغ 1,390,000ريال می‌توانید 70 عنوان مطلب دانلود کنید!
اشتراک سازمانی
به کتابخانه دانشگاه یا محل کار خود پیشنهاد کنید تا اشتراک سازمانی این پایگاه را برای دسترسی نامحدود همه کاربران به متن مطالب تهیه نمایند!
توجه!
  • حق عضویت دریافتی صرف حمایت از نشریات عضو و نگهداری، تکمیل و توسعه مگیران می‌شود.
  • پرداخت حق اشتراک و دانلود مقالات اجازه بازنشر آن در سایر رسانه‌های چاپی و دیجیتال را به کاربر نمی‌دهد.
In order to view content subscription is required

Personal subscription
Subscribe magiran.com for 70 € euros via PayPal and download 70 articles during a year.
Organization subscription
Please contact us to subscribe your university or library for unlimited access!