Visible to the public Detecting Stealthy Botnets in a Resource-Constrained Environment Using Reinforcement Learning

TitleDetecting Stealthy Botnets in a Resource-Constrained Environment Using Reinforcement Learning
Publication TypeConference Paper
Year of Publication2017
AuthorsVenkatesan, Sridhar, Albanese, Massimiliano, Shah, Ankit, Ganesan, Rajesh, Jajodia, Sushil
Conference NameProceedings of the 2017 Workshop on Moving Target Defense
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5176-8
Keywordsbotnets, honey pots, human factors, Intrusion detection, pubcrawl, reinforcement learning, resilience, Resiliency, Scalability
Abstract

Modern botnets can persist in networked systems for extended periods of time by operating in a stealthy manner. Despite the progress made in the area of botnet prevention, detection, and mitigation, stealthy botnets continue to pose a significant risk to enterprises. Furthermore, existing enterprise-scale solutions require significant resources to operate effectively, thus they are not practical. In order to address this important problem in a resource-constrained environment, we propose a reinforcement learning based approach to optimally and dynamically deploy a limited number of defensive mechanisms, namely honeypots and network-based detectors, within the target network. The ultimate goal of the proposed approach is to reduce the lifetime of stealthy botnets by maximizing the number of bots identified and taken down through a sequential decision-making process. We provide a proof-of-concept of the proposed approach, and study its performance in a simulated environment. The results show that the proposed approach is promising in protecting against stealthy botnets.

URLhttps://dl.acm.org/citation.cfm?doid=3140549.3140552
DOI10.1145/3140549.3140552
Citation Keyvenkatesan_detecting_2017