➥🔝 7737669865 🔝▻ malwa Call-girls in Women Seeking Men 🔝malwa🔝 Escorts Ser...
Botnet detection using cluster ensemble with cart
1. Botnet Detection Using Cluster
with CART Ensemble
Professor:
Student:
Sun Tae Chung
Trinh Dinh Phuc
(1101949014)
2. Contents
2
1. Overview of Botnet Detection.
2. Cluster & Classification and Regression Tree (CART) Ensemble.
3. Applies Cluster Ensemble and CART into detecting botnets.
3. Overview of Botnet Detection
3
A Botnet is a network of compromised computers under the control of a botmaster.
4. Definition of a flow: A flow is a group of packets that pass through
a router within a time interval.
All packets in a flow have same properties:
• Source IP
• Destination IP
• Source port
• Destination port
• Protocol (TCP, UDP, ...)
4
Overview of Botnet Detection
6. 6
Cluster & Classification and Regression Tree (CART)
Ensemble .
1. K-means
2. Classification and Regression (CART)
7. Applies Cluster and CART Ensemble into detecting botnets
Features Meaning
srcPort Source Port in a flow
dstPort Destination Port in a flow
l4Proto Protocol
avgPktRatio Average packet ratio (#bytes / #packets)
pktps The number of packets transferred per second
bytps The number of bytes transferred per second
conSrDrip The number of connection between source IP and destination IP
7
Data Overview:
8. Applies Cluster and CART Ensemble into detecting botnets
8
Classes Distribution:
9. Applies Cluster and CART Ensemble into detecting botnets
9
Techiques I have used:
• Feature Selection: Recursive Feature Elimination (RFE).
• Feature Scaling: Normalization.
• Feature Transformation: Label Encoder, One-hot Encoding.