Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F25%3A10133872" target="_blank" >RIV/63839172:_____/25:10133872 - isvavai.cz</a>
Nalezeny alternativní kódy
RIV/68407700:21240/25:00386912
Výsledek na webu
<a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297465" target="_blank" >http://dx.doi.org/10.23919/CNSM67658.2025.11297465</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297465" target="_blank" >10.23919/CNSM67658.2025.11297465</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic
Popis výsledku v původním jazyce
Detecting botnet Command-and-Control (C&C) communication in encrypted network traffic is a persistent challenge in cybersecurity, particularly in environments without endpoint visibility. We present a novel approach for botnet detection based on the inherent periodic communication patterns of C&C channels. Leveraging the Lomb-Scargle periodogram, we identify periodic behaviour in multiflow time series and extract periodic-based features for classification using machine learning. To address limitations in existing datasets, we introduce CESNET-CC25, a comprehensive and publicly available dataset comprising real-world botnet C&C traffic and benign traffic collected from an ISP backbone and controlled laboratory settings. Our method achieves high precision across both the widely used CTU-13 dataset and CESNET-CC25, with significant improvements in recall on long-duration captures. The results demonstrate that periodicity is a reliable indicator of C&C behaviour, even in modern, encrypted network environments, and that CESNET-CC25 provides a realistic benchmark for future botnet detection research.
Název v anglickém jazyce
Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic
Popis výsledku anglicky
Detecting botnet Command-and-Control (C&C) communication in encrypted network traffic is a persistent challenge in cybersecurity, particularly in environments without endpoint visibility. We present a novel approach for botnet detection based on the inherent periodic communication patterns of C&C channels. Leveraging the Lomb-Scargle periodogram, we identify periodic behaviour in multiflow time series and extract periodic-based features for classification using machine learning. To address limitations in existing datasets, we introduce CESNET-CC25, a comprehensive and publicly available dataset comprising real-world botnet C&C traffic and benign traffic collected from an ISP backbone and controlled laboratory settings. Our method achieves high precision across both the widely used CTU-13 dataset and CESNET-CC25, with significant improvements in recall on long-duration captures. The results demonstrate that periodicity is a reliable indicator of C&C behaviour, even in modern, encrypted network environments, and that CESNET-CC25 provides a realistic benchmark for future botnet detection research.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
Výsledek vznikl pri realizaci vícero projektů. Více informací v záložce Projekty.
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Proceedings of the 2025 21th International Conference on Network and Service Management CNSM 2025
ISBN
978-3-903176-75-1
ISSN
2165-963X
e-ISSN
—
Počet stran výsledku
6
Strana od-do
—
Název nakladatele
IEEE
Místo vydání
Bologna, Italy
Místo konání akce
Bologna, Italy
Datum konání akce
27. 10. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
—