Authors: Jovanović, Đorđe 
Vuletić, Pavle V.
Affiliations: Computer Science 
Mathematical Institute of the Serbian Academy of Sciences and Arts 
Title: PI-BODE: Programmable Intraflow-based IoT Botnet Detection system
Journal: Computer Science and Information Systems : ComSIS
Volume: 21
Issue: 1
First page: 37
Last page: 56
Issue Date: 2024
Rank: ~M23
ISSN: 1820-0214
DOI: 10.2298/CSIS211116064J
Abstract: 
In this paper, we propose a Programmable Intraflow-based IoT Botnet Detection (PI-BODE) system. PI-BODE is based on the detection of the Command and Control (C&C) communication between infected devices and the botmaster. This approach allows detecting malicious communication before any attacks occur. Unlike the majority of existing work, this detection method is based on the analysis of the traffic intraflow statistical parameters. Such an analysis makes the method more scalable and less hardware demanding in operation, while having a higher or equal level of detection accuracy compared to the packet capture based tools and methods. PI-BODE system leverages programmable network elements and Software Defined Networks (SDN) to extract intraflow features from flow time series in real time, while the flows are active. This procedure was verified on two datasets, whose data were gathered during the time span of more than two years: one captured by the authors of the paper and the other, IoT23.
Keywords: Botnet detection | IoT malware | Machine learning | programmable networks
Publisher: ComSIS Consotrium, Novi Sad

Files in This Item:
File Description SizeFormat
DJovanovic.pdf744.31 kBAdobe PDFView/Open
Show full item record

Page view(s)

153
checked on Nov 19, 2024

Download(s)

12
checked on Nov 19, 2024

Google ScholarTM

Check

Altmetric

Altmetric


This item is licensed under a Creative Commons License Creative Commons