{"id":"https://openalex.org/W3166939084","doi":"https://doi.org/10.1145/3460620.3460739","title":"Exposing Bot Attacks Using Machine Learning and Flow Level Analysis","display_name":"Exposing Bot Attacks Using Machine Learning and Flow Level Analysis","publication_year":2021,"publication_date":"2021-04-05","ids":{"openalex":"https://openalex.org/W3166939084","doi":"https://doi.org/10.1145/3460620.3460739","mag":"3166939084"},"language":"en","primary_location":{"id":"doi:10.1145/3460620.3460739","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460620.3460739","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Conference on Data Science, E-learning and Information Systems 2021","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5034699652","display_name":"Rana Faek","orcid":null},"institutions":[{"id":"https://openalex.org/I158749337","display_name":"Princess Sumaya University for Technology","ror":"https://ror.org/01jy46q10","country_code":"JO","type":"education","lineage":["https://openalex.org/I158749337"]}],"countries":["JO"],"is_corresponding":false,"raw_author_name":"Rana Faek","raw_affiliation_strings":["Princess Sumaya University for Technology, Jordan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Princess Sumaya University for Technology, Jordan","institution_ids":["https://openalex.org/I158749337"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102778422","display_name":"Mohammad Al-Fawa\u2019reh","orcid":"https://orcid.org/0000-0002-5621-4126"},"institutions":[{"id":"https://openalex.org/I158749337","display_name":"Princess Sumaya University for Technology","ror":"https://ror.org/01jy46q10","country_code":"JO","type":"education","lineage":["https://openalex.org/I158749337"]}],"countries":["JO"],"is_corresponding":false,"raw_author_name":"Mohammad Al-Fawa'reh","raw_affiliation_strings":["Princess Sumaya University for Technology, Jordan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Princess Sumaya University for Technology, Jordan","institution_ids":["https://openalex.org/I158749337"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5072460352","display_name":"Mustafa Al\u2010Fayoumi","orcid":"https://orcid.org/0000-0002-3129-5193"},"institutions":[{"id":"https://openalex.org/I158749337","display_name":"Princess Sumaya University for Technology","ror":"https://ror.org/01jy46q10","country_code":"JO","type":"education","lineage":["https://openalex.org/I158749337"]}],"countries":["JO"],"is_corresponding":false,"raw_author_name":"Mustafa Al-Fayoumi","raw_affiliation_strings":["Princess Sumaya University for Technology, Jordan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Princess Sumaya University for Technology, Jordan","institution_ids":["https://openalex.org/I158749337"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I158749337"],"apc_list":null,"apc_paid":null,"fwci":2.1704,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.87325581,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"99","last_page":"106"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.9906405806541443},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8126817941665649},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.7776122093200684},{"id":"https://openalex.org/keywords/netflow","display_name":"NetFlow","score":0.7064193487167358},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5904208421707153},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.5629357099533081},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.5246365666389465},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5127983689308167},{"id":"https://openalex.org/keywords/command-and-control","display_name":"Command and control","score":0.4433175027370453},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4248102009296417},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.39063769578933716},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.36631208658218384},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.15790647268295288}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.9906405806541443},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8126817941665649},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.7776122093200684},{"id":"https://openalex.org/C188067584","wikidata":"https://www.wikidata.org/wiki/Q219363","display_name":"NetFlow","level":2,"score":0.7064193487167358},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5904208421707153},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.5629357099533081},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.5246365666389465},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5127983689308167},{"id":"https://openalex.org/C506615639","wikidata":"https://www.wikidata.org/wiki/Q21662260","display_name":"Command and control","level":2,"score":0.4433175027370453},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4248102009296417},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.39063769578933716},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.36631208658218384},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.15790647268295288},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3460620.3460739","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460620.3460739","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Conference on Data Science, E-learning and Information Systems 2021","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W1586284606","https://openalex.org/W1963868908","https://openalex.org/W2003116136","https://openalex.org/W2026621111","https://openalex.org/W2031163547","https://openalex.org/W2093331366","https://openalex.org/W2099452399","https://openalex.org/W2117762361","https://openalex.org/W2154053567","https://openalex.org/W2169172206","https://openalex.org/W2187573866","https://openalex.org/W2332838062","https://openalex.org/W2460632868","https://openalex.org/W2570764787","https://openalex.org/W2618017145","https://openalex.org/W2789828921","https://openalex.org/W2798481441","https://openalex.org/W2968148850","https://openalex.org/W2973255066","https://openalex.org/W3005434770","https://openalex.org/W3036272524","https://openalex.org/W3082513339","https://openalex.org/W3085387668","https://openalex.org/W4246483628","https://openalex.org/W4298857589"],"related_works":["https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W4285325964","https://openalex.org/W4230824443","https://openalex.org/W2292210693","https://openalex.org/W2184748140","https://openalex.org/W2110675786","https://openalex.org/W2907510212","https://openalex.org/W3120717340","https://openalex.org/W2567044960"],"abstract_inverted_index":{"Botnets":[0],"represent":[1],"a":[2,133,138],"major":[3],"threat":[4],"to":[5,21,66,122,146],"Internet":[6],"security":[7],"that":[8,23,148],"have":[9],"continuously":[10],"developed":[11],"in":[12,50,64,78,119,142],"scale":[13],"and":[14,25,52,72,97,115],"complexity.":[15],"Command-and-control":[16],"servers":[17],"(C&C)":[18],"send":[19],"commands":[20],"bots":[22],"execute":[24],"perform":[26],"these":[27],"commands,":[28],"thereby":[29],"implementing":[30],"attacks":[31,49],"such":[32],"as":[33],"distributed":[34],"denial-of-service":[35],"(DDoS),":[36],"spam":[37],"campaigns,":[38],"or":[39,109],"the":[40,68,125,152,156],"scanning":[41],"of":[42,47,140],"compromised":[43],"hosts.":[44],"The":[45],"detection":[46,92,126,130],"volumetric":[48],"large":[51],"complex":[53],"networks":[54],"requires":[55],"an":[56],"efficient":[57,86],"mechanism.":[58],"Botnet":[59],"behavior":[60],"should":[61,75],"be":[62,76],"analyzed":[63],"order":[65],"save":[67],"network":[69],"from":[70],"attack,":[71],"preventive":[73],"measures":[74],"implemented":[77,137],"time.":[79],"Anomalous":[80],"botnet":[81,91,102],"tracking":[82],"strategies":[83],"are":[84],"more":[85],"than":[87],"signature-based":[88],"ones,":[89],"since":[90],"methods":[93],"rely":[94],"on":[95],"anomalies":[96],"do":[98],"not":[99],"need":[100],"pre-constructed":[101],"signatures,":[103],"therefore":[104],"they":[105],"can":[106],"detect":[107],"new":[108],"unidentified":[110],"botnets.":[111],"We":[112,136],"use":[113],"Netflow":[114],"machine":[116],"learning":[117],"algorithms":[118,131,141,157],"this":[120],"paper":[121],"also":[123],"improve":[124],"process":[127],"for":[128,155],"intrusion":[129],"with":[132],"novel":[134],"dataset.":[135],"number":[139],"our":[143],"lightweight":[144],"model":[145],"show":[147],"Random":[149],"Forests":[150],"get":[151],"highest":[153],"accuracy":[154],"used.":[158]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":2}],"updated_date":"2026-07-29T14:22:42.915294","created_date":"2025-10-10T00:00:00"}
