Information and Media Technologies
Online ISSN : 1881-0896
ISSN-L : 1881-0896
Computer Networks and Broadcasting
Mining Botnet Coordinated Attacks using Apriori-PrefixSpan Hybrid Algorithm
Masayuki OhruiHiroaki KikuchiNur Rohman RosyidMasato Terada
著者情報
キーワード: botnet, data-mining, Apriori, PrefixSpan
ジャーナル フリー

2013 年 8 巻 4 号 p. 1207-1216

詳細
抄録

This paper aims to detect features of coordinated attacks by applying data mining techniques, namely Apriori with PrefixSpan, to the CCC DATAset 2008-2010, which comprises captured packet data and downloading logs. Data mining algorithms enable us to automate the detection of characteristics in large amounts of data, which conventional heuristics cannot deal with. Apriori achieves a high recall but with false positives, whereas PrefixSpan has high precision but low recall. We therefore propose a hybrid of these two algorithms. Our analysis shows a change in the behavior of malware over the past three years.

著者関連情報
© 2013 Information Processing Society of Japan
前の記事 次の記事
feedback
Top