Botnet SPAM activities on networks require effective management due to their potential dangers, especially if they involve malware that infects computers. Previous studies introduced botnet model detection focusing on binary class detection to recognize botnet activity and normal activity. Meanwhile, there are challenges to detecting specific botnet attack activities such as SPAM activities. This paper presents an approach utilizing ensemble multi-label classification for the detection of SPAM attacks executed by botnets. The proposed method involves four stages: data preparation, labeling, splitting, and ensemble classification. In the data preparation phase, binary encoding enhances feature representation, while the labeling process categorizes instances into normal, botnet attack (Non SPAM), and botnet SPAM attack for comprehensive analysis. Using the Stratified k-Fold approach in data splitting ensures balanced representation in training and testing sets to address dataset imbalances. Then, in the classification phase, this research combines a Decision Tree, Random Forest, k-nearest Neighbors, Naïve Bayes, and Logistic Regression algorithm with an ensemble “hard” voting strategy. The proposed model achieves the highest accuracy detection performance of 99.05%, demonstrating the effectiveness of the ensemble in detecting SPAM botnet activity. Additionally, the ensembles exhibit adaptability and robustness, offering administrators valuable insights for decision-making in managing attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Botnet SPAM Detection Through a Robust Ensemble Classification Approach

  • Frederick Yonatan Susanto,
  • Tohari Ahmad,
  • Dandy Pramana Hostiadi,
  • Muhammad Aidiel Rachman Putra

摘要

Botnet SPAM activities on networks require effective management due to their potential dangers, especially if they involve malware that infects computers. Previous studies introduced botnet model detection focusing on binary class detection to recognize botnet activity and normal activity. Meanwhile, there are challenges to detecting specific botnet attack activities such as SPAM activities. This paper presents an approach utilizing ensemble multi-label classification for the detection of SPAM attacks executed by botnets. The proposed method involves four stages: data preparation, labeling, splitting, and ensemble classification. In the data preparation phase, binary encoding enhances feature representation, while the labeling process categorizes instances into normal, botnet attack (Non SPAM), and botnet SPAM attack for comprehensive analysis. Using the Stratified k-Fold approach in data splitting ensures balanced representation in training and testing sets to address dataset imbalances. Then, in the classification phase, this research combines a Decision Tree, Random Forest, k-nearest Neighbors, Naïve Bayes, and Logistic Regression algorithm with an ensemble “hard” voting strategy. The proposed model achieves the highest accuracy detection performance of 99.05%, demonstrating the effectiveness of the ensemble in detecting SPAM botnet activity. Additionally, the ensembles exhibit adaptability and robustness, offering administrators valuable insights for decision-making in managing attacks.