Journal of Cybersecurity and Information Management
JCIM
2690-6775
2769-7851
10.54216/JCIM
https://www.americaspg.com/journals/show/837
2019
2019
Performance Analysis of Machine Learning based Botnet Detection and Classification Models for Information Security
Professor of Computer Science, Ibn Zohr University, Agadir, Morocco
Ahmed A.
Elngar
Botnet detection becomes a challenging issue in several domains like cybersecurity, finance, healthcare, law, order, etc. The botnet represents a set of cooperated Internet-linked devices managed by cyber criminals to start coordinated attacks and carry out different malicious events. As the botnets are seamlessly dynamic with the developing countermeasures presented by network and host-based detection schemes, conventional methods have failed to achieve enough safety for botnet threats. Therefore, machine learning (ML) models have been developed to detect and classify botnets for cybersecurity. In this view, this paper performs a comprehensive evaluation of different ML-based botnet detection and classification models. The botnet detection model involves a three-stage process, namely preprocessing, feature extraction, and classification. In this study, four ML models such as C4.5 Decision Tree, bagging, boosting, and Adaboost are employed for classification purposes. To highlight the performance of the four ML models, an extensive set of simulations was performed. The obtained results pointed out that the ML models can attain enhanced botnet detection performance.
2019
2019
44
53
10.54216/JCIM.000104
https://www.americaspg.com/articleinfo/2/show/837