Vše

Co hledáte?

Vše
Projekty
Výsledky výzkumu
Subjekty

Rychlé hledání

  • Projekty podpořené TA ČR
  • Významné projekty
  • Projekty s nejvyšší státní podporou
  • Aktuálně běžící projekty

Chytré vyhledávání

  • Takto najdu konkrétní +slovo
  • Takto z výsledků -slovo zcela vynechám
  • “Takto můžu najít celou frázi”

Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic

Identifikátory výsledku

  • Kód výsledku v IS VaVaI

    <a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F25%3A10133872" target="_blank" >RIV/63839172:_____/25:10133872 - isvavai.cz</a>

  • Nalezeny alternativní kódy

    RIV/68407700:21240/25:00386912

  • Výsledek na webu

    <a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297465" target="_blank" >http://dx.doi.org/10.23919/CNSM67658.2025.11297465</a>

  • DOI - Digital Object Identifier

    <a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297465" target="_blank" >10.23919/CNSM67658.2025.11297465</a>

Alternativní jazyky

  • Jazyk výsledku

    angličtina

  • Název v původním jazyce

    Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic

  • Popis výsledku v původním jazyce

    Detecting botnet Command-and-Control (C&amp;C) communication in encrypted network traffic is a persistent challenge in cybersecurity, particularly in environments without endpoint visibility. We present a novel approach for botnet detection based on the inherent periodic communication patterns of C&amp;C channels. Leveraging the Lomb-Scargle periodogram, we identify periodic behaviour in multiflow time series and extract periodic-based features for classification using machine learning. To address limitations in existing datasets, we introduce CESNET-CC25, a comprehensive and publicly available dataset comprising real-world botnet C&amp;C traffic and benign traffic collected from an ISP backbone and controlled laboratory settings. Our method achieves high precision across both the widely used CTU-13 dataset and CESNET-CC25, with significant improvements in recall on long-duration captures. The results demonstrate that periodicity is a reliable indicator of C&amp;C behaviour, even in modern, encrypted network environments, and that CESNET-CC25 provides a realistic benchmark for future botnet detection research.

  • Název v anglickém jazyce

    Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic

  • Popis výsledku anglicky

    Detecting botnet Command-and-Control (C&amp;C) communication in encrypted network traffic is a persistent challenge in cybersecurity, particularly in environments without endpoint visibility. We present a novel approach for botnet detection based on the inherent periodic communication patterns of C&amp;C channels. Leveraging the Lomb-Scargle periodogram, we identify periodic behaviour in multiflow time series and extract periodic-based features for classification using machine learning. To address limitations in existing datasets, we introduce CESNET-CC25, a comprehensive and publicly available dataset comprising real-world botnet C&amp;C traffic and benign traffic collected from an ISP backbone and controlled laboratory settings. Our method achieves high precision across both the widely used CTU-13 dataset and CESNET-CC25, with significant improvements in recall on long-duration captures. The results demonstrate that periodicity is a reliable indicator of C&amp;C behaviour, even in modern, encrypted network environments, and that CESNET-CC25 provides a realistic benchmark for future botnet detection research.

Klasifikace

  • Druh

    D - Stať ve sborníku

  • CEP obor

  • OECD FORD obor

    10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)

Návaznosti výsledku

  • Projekt

    Výsledek vznikl pri realizaci vícero projektů. Více informací v záložce Projekty.

  • Návaznosti

    P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)

Ostatní

  • Rok uplatnění

    2025

  • Kód důvěrnosti údajů

    S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů

Údaje specifické pro druh výsledku

  • Název statě ve sborníku

    Proceedings of the 2025 21th International Conference on Network and Service Management CNSM 2025

  • ISBN

    978-3-903176-75-1

  • ISSN

    2165-963X

  • e-ISSN

  • Počet stran výsledku

    6

  • Strana od-do

  • Název nakladatele

    IEEE

  • Místo vydání

    Bologna, Italy

  • Místo konání akce

    Bologna, Italy

  • Datum konání akce

    27. 10. 2025

  • Typ akce podle státní příslušnosti

    WRD - Celosvětová akce

  • Kód UT WoS článku