PI-BODE: Programmable Intraflow-based IoT Botnet Detection system
Computer Science and Information Systems, Tome 21 (2024) no. 1.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

In this paper, we propose a Programmable Intraflow-based IoT Botnet Detection (PI-BODE) system. PI-BODE is based on the detection of the Command and Control (C) communication between infected devices and the botmaster. This approach allows detecting malicious communication before any attacks occur. Unlike the majority of existing work, this detection method is based on the analysis of the traffic intraflow statistical parameters. Such an analysis makes the method more scalable and less hardware demanding in operation, while having a higher or equal level of detection accuracy compared to the packet capture based tools and methods. PI-BODE system leverages programmable network elements and Software Defined Networks (SDN) to extract intraflow features from flow time series in real time, while the flows are active. This procedure was verified on two datasets, whose data were gathered during the time span of more than two years: one captured by the authors of the paper and the other, IoT23.
Keywords: Botnet detection, Machine learning, IoT malware, programmable networks
@article{CSIS_2024_21_1_a6,
     author = {{\DJ}or{\dj}e D. Jovanovi\'c and Pavle V. Vuleti\'c},
     title = {PI-BODE: {Programmable} {Intraflow-based} {IoT} {Botnet} {Detection} system},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {21},
     number = {1},
     year = {2024},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2024_21_1_a6/}
}
TY  - JOUR
AU  - Đorđe D. Jovanović
AU  - Pavle V. Vuletić
TI  - PI-BODE: Programmable Intraflow-based IoT Botnet Detection system
JO  - Computer Science and Information Systems
PY  - 2024
VL  - 21
IS  - 1
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2024_21_1_a6/
ID  - CSIS_2024_21_1_a6
ER  - 
%0 Journal Article
%A Đorđe D. Jovanović
%A Pavle V. Vuletić
%T PI-BODE: Programmable Intraflow-based IoT Botnet Detection system
%J Computer Science and Information Systems
%D 2024
%V 21
%N 1
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2024_21_1_a6/
%F CSIS_2024_21_1_a6
Đorđe D. Jovanović; Pavle V. Vuletić. PI-BODE: Programmable Intraflow-based IoT Botnet Detection system. Computer Science and Information Systems, Tome 21 (2024) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2024_21_1_a6/