Presentation is loading. Please wait.

Presentation is loading. Please wait.

Integrating BotMiner and SNARE into SMITE Nick Feamster and Wenke Lee Students: Shuang Hao and Junjie Zhang Georgia Tech.

Similar presentations


Presentation on theme: "Integrating BotMiner and SNARE into SMITE Nick Feamster and Wenke Lee Students: Shuang Hao and Junjie Zhang Georgia Tech."— Presentation transcript:

1 Integrating BotMiner and SNARE into SMITE Nick Feamster and Wenke Lee Students: Shuang Hao and Junjie Zhang Georgia Tech

2 Current Status Implementations using flows from pipeline –SNARE (Perl + R), uses SMTP (port 25) –BotMiner (Java + R + MySQL) Offline performance evaluation BotMiner SNARE

3 Evaluation Configuration: –1 day of packet capture from university network –2-processor dual-core Intel Xeon 2.0 GHz, with 8 GB of RAM SNARE –Extract features (Perl): seconds, 72 MB –Training (R): seconds, 3.3 GB –Detection time (R): 3.13 seconds, 120 MB BotMiner –Prune, insert into DB: 25,200 seconds –Aggregate c-flows: 61 seconds –Cross-plane correlation: 175 seconds

4 Next Steps Re-design aspects of SNARE for online detection (currently, works on labeled datasets) Online evaluation in the university network Applying sampling to improve the performance


Download ppt "Integrating BotMiner and SNARE into SMITE Nick Feamster and Wenke Lee Students: Shuang Hao and Junjie Zhang Georgia Tech."

Similar presentations


Ads by Google