Marchat, V. (2026). Detection of Botnet Command-and-Control Communication Using Long Short-Term Memory Networks [Diploma Thesis, Technische Universität Wien]. reposiTUm. https://doi.org/10.34726/hss.2026.140745
Botnet-Erkennung; Netzwerk Sicherheit; Machinelles Lernen; Long Short-Term Memory
de
Botnet Detection; Network Security; Machine Learning; Long Short-Term Memory
en
Abstract:
Diese Arbeit beschäftigt sich mit der Erkennung von Botnet ’Command-and-Control’-(C&C) Kommunikation unter Verwendung maschineller Lernalgorithmen. Das vorrangige Ziel bestand darin, zu bewerten, ob paketbasierte ’Long Short-Term Memory’ (LSTM)-Netzwerke schädliche C&C-Kommunikation wirksam von legitimem Netzwerkverkehr unterscheiden können und wie ihre Leistung im Vergleich zu herkömmlichen paket- und flowbasierten Ansätzen des maschinellen Lernens abschneidet.Um dieses Ziel zu erreichen, wurde ein umfassendes Framework zur Extraktion, Vorverarbeitung und Klassifizierung von Netzwerkverkehr auf Paketebene aus ausgewählten Datensätzen in der Fachliteratur entwickelt. Das Framework umfasst eine Implementierung des LSTM-Algorithmus zur Klassifizierung von Netzwerkpaketen, kombiniert mit einer Implementierung des Salp-Swarm-Algorithmus (SSA), um eine automatische Hyperparameteroptimierung der LSTM-Netzwerke zu ermöglichen. Unter mehreren untersuchten Netzwerkverkehr-Datensätzen wurden der „Aposemat-IoT-23“ und „CESNET-CC25“ als zwei der in der Literatur am besten geeigneten Datensätze für die paketbasierte C&C-Erkennung identifiziert. Eine umfassende explorative Datenanalyse wurde durchgeführt, um die Qualität, die Merkmalsverteilungen, das Klassenungleichgewicht und die Merkmalskorrelationen des legitimen und bösartigen Netzwerkverkehrs beider Datensätze zu bewerten. Mithilfe der analysierten Daten und des vorgeschlagenen Frameworks wurden mehrere LSTM-Klassifikatoren mit unterschiedlichen Kombinationen von Paketmerkmalen auf den beiden Datensätzen trainiert. Die Ergebnisse belegten, dass paketbasierte LSTM-Modelle in der Lage sind, bei den evaluierten Datensätzen nahezu perfekte Vorhersagen über die Klasse der Pakete zu treffen, während die Modelle nur bis zu drei unterschiedliche Paketmerkmale benötigen. Darüber hinaus werden paketbasierte und flowbasierte Random-Forest-Modelle (RF) anhand derselben Datensätze trainiert. Ein quantitativer Vergleich der von den RF- und LSTM-Modellen produzierten Klassifikationsergebnisse wird auf Grundlage des F1-Scores als Metrik durchgeführt. Im Durchschnitt schneiden die LSTM-Modelle besser ab als die paketbasierten RF-Modelle, während die flowbasierten RF-Modelle eine Leistung erzielen, die mit der der paketbasierten LSTM-Modelle vergleichbar ist.
de
In this thesis, the detection of botnet Command-and-Control (C&C) communication using machine learning techniques with a particular focus on packet-based network traffic analysis is investigated. The primary objective is to evaluate whether packet-based Long Short-Term Memory (LSTM) networks can effectively distinguish malicious C&C communication from benign network traffic and how their performance compares to traditional packet- and flow-based machine learning approaches.To address this objective, a complete framework is developed for extracting, preprocessing and classifying packet-level network traffic from selected datasets in the literature. The framework includes packet-processing components capable of transforming raw network traffic recordings into machine-learning-ready datasets as well as an implementation of the LSTM algorithm for the classification of network packets. In addition, the Salp Swarm Algorithm (SSA) is integrated into the framework for automatic hyperparameter optimization of LSTM networks. Among several examined network traffic datasets, the Aposemat-IoT-23 and CESNETCC25 were identified as two of the most suitable datasets for packet-based C&C detection in the literature. An extensive exploratory data analysis is conducted to assess quality, feature distributions, class imbalance, and feature correlations on benign and malicious network traffic of both datasets. Several LSTM classifiers are trained with different packet feature combinations on the two datasets by means of the explored data and the proposed framework. The results demonstrated that packet-based LSTM models are capable of making nearly perfect predictions about the class of packets in the evaluated datasets, while the models require only up to three different packet features. In addition, packet-based and flow-based Random Forest (RF) models are trained using the same datasets. A quantitative comparison of the RF and LSTM models is performed based on the balanced F1-score. On average, the LSTM models outperform the packet-based RF models, while the flow-based RF models achieve performance comparable to that of the packet-based LSTM models.
en
Additional information:
Arbeit an der Bibliothek noch nicht eingelangt - Daten nicht geprüft