Evading botnet detectors based on flows and random forest with adversarial samples
Dagsetning
Höfundar
Journal Title
Journal ISSN
Volume Title
Útgefandi
Institute of Electrical and Electronics Engineers Inc.
Útdráttur
Machine learning is increasingly adopted for a wide array of applications, due to its promising results and autonomous capabilities. However, recent research efforts have shown that, especially within the image processing field, these novel techniques are susceptible to adversarial perturbations. In this paper, we present an analysis that highlights and evaluates experimentally the fragility of network intrusion detection systems based on machine learning algorithms against adversarial attacks. In particular, our study involves a random forest classifier that utilizes network flows to distinguish between botnet and benign samples. Our results, derived from experiments performed on a public real dataset of labelled network flows, show that attackers can easily evade such defensive mechanisms by applying slight and targeted modifications to the network activity generated by their controlled bots. These findings pave the way for future techniques that aim to strengthen the performance of machine learning-based network intrusion detection systems.
Lýsing
Publisher Copyright: © 2018 IEEE.
Efnisorð
Adversarial samples, botnet, flow inspection, intrusion detection, machine learning, random forest, Computer Networks and Communications, Computer Science Applications, Safety, Risk, Reliability and Quality
Citation
Apruzzese, G & Colajanni, M 2018, Evading botnet detectors based on flows and random forest with adversarial samples. in NCA 2018 - 2018 IEEE 17th International Symposium on Network Computing and Applications., 8548327, NCA 2018 - 2018 IEEE 17th International Symposium on Network Computing and Applications, Institute of Electrical and Electronics Engineers Inc., 17th IEEE International Symposium on Network Computing and Applications, NCA 2018, Cambridge, United States, 1/11/18. https://doi.org/10.1109/NCA.2018.8548327
conference
conference