Related Experiment Video
Updated: Dec 11, 2025

08:30
Characterization of Aquatic Biofilms with Flow Cytometry
Published on: June 6, 2018
9.5K
Benchmark-Based Reference Model for Evaluating Botnet Detection Tools Driven by Traffic-Flow Analytics
Katherinne Shirley Huancayo Ramos1, Marco Antonio Sotelo Monge1, Jorge Maestre Vidal2
1Faculty of Engineering and Architecture, Universidad de Lima, Avenida Javier Prado Este, 4600 Lima 33, Peru.
Sensors (Basel, Switzerland)
|August 19, 2020
Summary
This study introduces a novel evaluation scheme using supervised machine learning to detect and differentiate botnet families. Random Forest and Decision Tree models show superior performance in identifying botnets with high precision and efficiency.
Area of Science:
- Cybersecurity
- Network Security
- Machine Learning
Background:
- Botnets pose recurrent cyber-threats, exploiting diverse endpoint devices at the network edge.
- Accurate botnet detection methods are crucial for effective defensive strategies, requiring robust evaluation models.
Purpose of the Study:
- To introduce a novel evaluation scheme for detecting and discriminating botnet families in operational environments.
- To develop a detection model for botnet-related malware using supervised machine learning algorithms.
Main Methods:
- Observing and inferring botnet family behavior from network flow-level indicators.
- Implementing and comparing five supervised classifiers: Decision Tree, Random Forest, Naive Bayes Gaussian, Support Vector Machine, and K-Neighbors.
- Utilizing Grid Search for optimizing algorithm performance on heterogeneous datasets.
Main Results:
- Random Forest and Decision Tree models demonstrated the highest suitability for botnet detection among the tested algorithms.
- These models achieved higher precision rates and processed large sample volumes with reduced processing time.
- Experimental validation was performed on CIC-AWS-2018 and ISOT HTTP Botnet datasets.
Conclusions:
- The proposed evaluation scheme is adequate for detecting diverse botnet specimens.
- Random Forest and Decision Tree algorithms are recommended for flow-based botnet detection due to their efficiency and precision.
- The study establishes baseline results for future benchmark analyses in botnet detection.