dc.creatorGarcía, Sebastián
dc.creatorGrill, M.
dc.creatorStiborek, J.
dc.creatorZunino Suarez, Alejandro Octavio
dc.date.accessioned2016-07-28T19:30:27Z
dc.date.accessioned2018-11-06T14:15:39Z
dc.date.available2016-07-28T19:30:27Z
dc.date.available2018-11-06T14:15:39Z
dc.date.created2016-07-28T19:30:27Z
dc.date.issued2014-06
dc.identifierGarcía, Sebastián; Grill, M.; Stiborek, J.; Zunino Suarez, Alejandro Octavio; An Empirical Comparison of Botnet Detection Methods; Elsevier; Computers & Security; 45; 6-2014; 100-123
dc.identifier0167-4048
dc.identifierhttp://hdl.handle.net/11336/6772
dc.identifier.urihttp://repositorioslatinoamericanos.uchile.cl/handle/2250/1884494
dc.description.abstractThe results of botnet detection methods are usually presented without any comparison. Although it is generally accepted that more comparisons with third-party methods may help to improve the area, few papers could do it. Among the factors that prevent a comparison are the difficulties to share a dataset, the lack of a good dataset, the absence of a proper description of the methods and the lack of a comparison methodology. This paper compares the output of three different botnet detection methods by executing them over a new, real, labeled and large botnet dataset. This dataset includes botnet, normal and background traffic. The results of our two methods (BClus and CAMNEP) and BotHunter were compared using a methodology and a novel error metric designed for botnet detections methods. We conclude that comparing methods indeed helps to better estimate how good the methods are, to improve the algorithms, to build better datasets and to build a comparison methodology.
dc.languageeng
dc.publisherElsevier
dc.relationinfo:eu-repo/semantics/altIdentifier/url/http://www.sciencedirect.com/science/article/pii/S0167404814000923
dc.relationinfo:eu-repo/semantics/altIdentifier/doi/http://dx.doi.org/10.1016/j.cose.2014.05.011
dc.relationinfo:eu-repo/semantics/altIdentifier/doi/10.1016/j.cose.2014.05.011
dc.rightshttps://creativecommons.org/licenses/by-nc-nd/2.5/ar/
dc.rightsinfo:eu-repo/semantics/restrictedAccess
dc.subjectBotnet detection
dc.subjectMalware detection
dc.subjectMethods comparison
dc.subjectBotnet dataset
dc.subjectAnomaly detection
dc.subjectNetwork traffic
dc.titleAn Empirical Comparison of Botnet Detection Methods
dc.typeArtículos de revistas
dc.typeArtículos de revistas
dc.typeArtículos de revistas


Este ítem pertenece a la siguiente institución