Skip to main content

Table 5 Detection result with similarity approach

From: B-CAT: a model for detecting botnet attacks using deep attack behavior analysis on network traffic flows

Dataset source

Scenario/sensor

TP

FP

TN

FN

Accuracy (%)

Precision (%)

Recall (%)

CTU-13

1

38,654

0

2,783,675

2307

99.92

100

94.37

2

20,050

0

1,787,181

891

99.95

100

95.75

3

26,759

63

4,683,753

63

100

99.77

99.77

4

2580

0

1,118,496

0

100

100

100

5

901

0

128,931

0

100

100

100

6

4042

0

554,289

588

99.89

100

87.30

7

63

0

114,014

0

100

100

100

8

5794

0

2,948,103

333

99.99

100

94.57

9

183,196

0

1,902,521

1791

99.91

100

99.03

10

106,352

5

1,203,434

0

100

100

100

11

8164

0

99,087

0

100

100

100

12

2143

25

323,278

25

99.98

98.85

98.85

13

38,547

0

1,885,146

1456

99.92

100

96.36

Average

99.97

99.89

97.38

NCC-1

1

22,576

0

2,089,224

424

99.98

100

98.16

2

23,944

0

1,441,182

56

100

100

99.77

3

798

1000

2,902,611

1202

99.92

44.38

39.90

4

10,957

0

713,388

43

99.99

100

99.61

5

19,000

0

73,917

0

100

100

100

6

5954

0

506,021

46

99.99

100

99.23

7

8881

0

74,473

119

99.86

100

98.68

8

13,804

0

2,857,217

196

99.99

100

98.60

9

217,452

0

1,353,304

2548

99.84

100

98.84

10

57,397

0

924,369

2603

99.74

100

95.66

11

12,000

0

18,964

0

100

100

100

12

2821

6000

259,186

6,179

95.56

31.98

31.34

13

18,864

0

1,857,489

136

99.99

100

99.28

Average

99.60

90.49

89.16

NCC-2

1

140,364

0

4,749,158

5636

99.88

100

96.14

2

354,918

0

5,634,133

9082

99.85

100

97.50

3

289,620

0

3,591,792

4380

99.89

100

98.51

Average

99.87

100

97.38