Employing machine learning algorithms to detect unknown scanning and email worms

المؤلفون المشاركون

al-Nasiri, Amir
Abd Allah, Shubayr
Ramadass, Sureswaran
al-Tayyib, al-Tayyib al-Tahir

المصدر

The International Arab Journal of Information Technology

العدد

المجلد 11، العدد 2 (31 مارس/آذار 2014)9ص.

الناشر

جامعة الزرقاء

تاريخ النشر

2014-03-31

دولة النشر

الأردن

عدد الصفحات

9

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الموضوعات

الملخص EN

we present a worm detection system that leverages the reliability of IP-Flow and the effectiveness of learning machines.

Typically, a host infected by a scanning or an email worm initiates a significant amount of traffic that does not rely on DNS to translate names into numeric IP addresses.

Based on this fact, we capture and classify NetFlow records to extract feature patterns for each PC on the network within a certain period of time.

A feature pattern includes: no of DNS requests, no of DNS responses, no of DNS normals, and no of DNS anomalies.

Two learning machines are used, K-Nearest Neighbors (KNN) and Naïve Bayes (NB), for the purpose of classification.

Solid statistical tests, the cross-validation and paired t-test, are conducted to compare the individual performance between the KNN and NB algorithms.

We used the classification accuracy, false alarm rates, and training time as metrics of performance to conclude which algorithm is superior to another.

The data set used in training and testing the algorithms is created by using 18 real-life worm variants along with a big amount of benign flows.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Abd Allah, Shubayr& Ramadass, Sureswaran& al-Tayyib, al-Tayyib al-Tahir& al-Nasiri, Amir. 2014. Employing machine learning algorithms to detect unknown scanning and email worms. The International Arab Journal of Information Technology،Vol. 11, no. 2.
https://search.emarefa.net/detail/BIM-334208

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Abd Allah, Shubayr…[et al.]. Employing machine learning algorithms to detect unknown scanning and email worms. The International Arab Journal of Information Technology Vol. 11, no. 2 (Mar. 2014).
https://search.emarefa.net/detail/BIM-334208

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Abd Allah, Shubayr& Ramadass, Sureswaran& al-Tayyib, al-Tayyib al-Tahir& al-Nasiri, Amir. Employing machine learning algorithms to detect unknown scanning and email worms. The International Arab Journal of Information Technology. 2014. Vol. 11, no. 2.
https://search.emarefa.net/detail/BIM-334208

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-334208