Towards effective reproducible botnet detection methods through scientific workflow management systems

  • Frederico Tosta de Oliveira
  • Maria Claudia Cavalcanti
  • Ronaldo Moreira Salles

Resumo


Even after nearly two decades of the creation of the first botnet, the detection and mitigation of their attacks remain one of the biggest challenges faced by researchers and cyber-security professionals. Although there are numerous studies related to botnet detection, estimating how much one method is better than another is still an open problem, mainly because of the difficulty in comparing and reproducing such methods. This work proposes an architecture, implemented with Spark as a high-performance data processing solution, together with VisTrails as a workflow management and data provenance solution, to address this comparability and reproducibility problem in a large-scale environment, as well as a tool, ProvTracker, to analyze and compare the methods results. Another contribution is on the way to couple these two technologies so that intermediary data is maintained available during several partial (re)executions of the experiments involved in each method, minimizing the impact on the analysis of the large amount of data involved.
Publicado
19/05/2017
Como Citar

Selecione um Formato
OLIVEIRA, Frederico Tosta de; CAVALCANTI, Maria Claudia; SALLES, Ronaldo Moreira. Towards effective reproducible botnet detection methods through scientific workflow management systems. In: SIMPÓSIO BRASILEIRO DE REDES DE COMPUTADORES E SISTEMAS DISTRIBUÍDOS (SBRC), 35. , 2017, Belém. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2017 . ISSN 2177-9384.