Since the recent pandemic, many organizations have seen a significant increase in threats against their IT infrastructure due to the very quick expansion of the attack surface. Indeed, remote working and remote caring have required a rush of new digital services, often created swiftly, and arranged, with operators often not strongly prepared in terms of cyber security awareness. Botnets are one of the most increasing means of attack that, often, represent an enabling technology for DDoS, theft, spam, and malware injection, among the most dangerous and damaging threats. Artificial Intelligence and, specifically, Machine Learning technology is extremely promising for countering many cybersecurity menaces, botnets in particular, because they can detect previously unknown command & control and deployment tactics. This paper presents a simple botnet detection experience, based on the Network Anomaly Detection approach and leveraging Machine Learning technologies. The work starts from the outcomes of previous research efforts with the final aim of producing a system that can be used in a real environment. This is the first step of more complex work to create a reliable Machine Learning system that could support legacy methods to detect cyber-security attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Deep Learning Techniques for Botnet Detection

  • Antonio Scarfò

摘要

Since the recent pandemic, many organizations have seen a significant increase in threats against their IT infrastructure due to the very quick expansion of the attack surface. Indeed, remote working and remote caring have required a rush of new digital services, often created swiftly, and arranged, with operators often not strongly prepared in terms of cyber security awareness. Botnets are one of the most increasing means of attack that, often, represent an enabling technology for DDoS, theft, spam, and malware injection, among the most dangerous and damaging threats. Artificial Intelligence and, specifically, Machine Learning technology is extremely promising for countering many cybersecurity menaces, botnets in particular, because they can detect previously unknown command & control and deployment tactics. This paper presents a simple botnet detection experience, based on the Network Anomaly Detection approach and leveraging Machine Learning technologies. The work starts from the outcomes of previous research efforts with the final aim of producing a system that can be used in a real environment. This is the first step of more complex work to create a reliable Machine Learning system that could support legacy methods to detect cyber-security attacks.