dc.contributor.author |
Al Ebri, Noura |
|
dc.contributor.author |
Otrok, Hadi |
|
dc.contributor.author |
Mourad, Azzam |
|
dc.contributor.author |
Al-Hammadi, Yousof |
|
dc.date.accessioned |
2017-03-10T08:44:44Z |
|
dc.date.available |
2017-03-10T08:44:44Z |
|
dc.date.issued |
2017-03-10 |
|
dc.identifier.isbn |
9781467353076 |
en_US |
dc.identifier.uri |
http://hdl.handle.net/10725/5351 |
|
dc.description.abstract |
In this paper, we address the problem of botnet detection by correlating information from trusted hosts and network. Botnets are groups of compromised computers controlled by a botmaster through a command and control (C&C) channel. They are noted as one of the foremost security threat causing large scale attacks such as Distributed Denial of Service (DDoS), Spam, mass identity theft and click fraud. Various approaches are used to detect botnets and they range from network to host level detection. To enhance the detection rate, a correlation based model was proposed that combines both host and network level information. Such a model is valid in a network made of trusted hosts. The emergence of smartphones with the capability of mobility and being hosts in different networks, open the door of having untrusted hosts that can reveal fake information. As a solution, we propose a trust-based model that uses cooperative game theory to cluster trusted hosts. The trust is built using the reputation value and it is computed using the hosts' marginal contribution which is derived from Shapley value. Simulation results show that our model improves the detection score compared to the traditional correlation model. Where in one of the simulated scenarios we are able to detect a benign cluster of hosts faster than the traditional correlation model. |
en_US |
dc.language.iso |
en |
en_US |
dc.publisher |
IEEE |
en_US |
dc.title |
Botnet detection |
en_US |
dc.type |
Conference Paper / Proceeding |
en_US |
dc.title.subtitle |
a cooperative game theoretical correlation-based model |
en_US |
dc.author.school |
SAS |
en_US |
dc.author.idnumber |
200904853 |
en_US |
dc.author.department |
Computer Science and Mathematics |
en_US |
dc.description.embargo |
N/A |
en_US |
dc.keywords |
Correlation |
en_US |
dc.keywords |
Security |
en_US |
dc.keywords |
Games |
en_US |
dc.keywords |
Game theory |
en_US |
dc.keywords |
Computational modeling |
en_US |
dc.keywords |
Ports (Computers) |
en_US |
dc.keywords |
Data models |
en_US |
dc.identifier.doi |
http://dx.doi.org/10.1109/ICCITechnology.2013.6579517 |
en_US |
dc.identifier.ctation |
Al Ebri, N., Otrok, H., Mourad, A., & Al-Hammadi, Y. (2013, June). Botnet detection: A cooperative game theoretical correlation-based model. In Communications and Information Technology (ICCIT), 2013 Third International Conference on (pp. 28-32). IEEE. |
en_US |
dc.author.email |
azzam.mourad@lau.edu.lb |
en_US |
dc.conference.date |
19-21 June 2013 |
en_US |
dc.conference.pages |
28-32 |
en_US |
dc.conference.place |
Beirut, Lebanon |
en_US |
dc.conference.title |
2013 Third International Conference on Communications and Information Technology |
en_US |
dc.identifier.tou |
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php |
en_US |
dc.identifier.url |
http://ieeexplore.ieee.org/abstract/document/6579517/ |
en_US |
dc.orcid.id |
https://orcid.org/0000-0001-9434-5322 |
|
dc.author.affiliation |
Lebanese American University |
en_US |