2017
Flow based botnet detection through semi-supervised active learning
ICASSP 2017accepted
In a variety of Network-based Intrusion Detection System (NIDS) applications, one desires to detect groups of unknown attack (e.g., botnet) packet-flows, with a group potentially manifesting its a typicality (relative to a known reference “normal”/null model) on a low-dimensional subset of the full…