Private:progress-alkurbi
From NMSL
Spring 2011
- Courses: None
- Research: Developing Online SIP-Botnet Detection System
- Progress Report: Please read "Progress" section here
Feb 08
- Rewrite the experiments and evaluation results in a formal manner under "`Experimental Evaluation"' chapter. (Done)
- Implementing \& Testing Identifying Sip-Botnet controllers. (Done)
- Implementing and testing Test Online Mode. (Done)
Feb 01
- Evaluation according to the plan (Large Scale Evaluation & Documentation) is complete, as following:
- Generated Traffics have been checked.
- Alpha & Beta has been tuned.
- Different traffic have been generated for different number of bots [10, 50, 100].
- FP/FN has been calculated for different Win [1h, 2h, 3h], and for different Sliding-Win [5m, 10m, 15m, 20m, 25m, 30m], with different number of bots.
- Average running time has been computed for different Win [1h, 2h, 3h] and different number of bots [10, 50, 100].
- A total of 34 figures have been plotted and included in the report.
- The attached report has all the update.
Jan 24
- Works (Large Scale Evaluation & Documentation):
- Generated 24h SIP traffic with "1000" users, "10" bots.
- Tuned Alpha & Beta values.
- Ran the proposed system against the generated traffic with different win sizes (3h, 2h), and different Sliding-Win sizes (5m, 10m, 15m, 20m, 25m, 30m), to calculate False Positives/Negatives, and generated 12 statistics reports.
- Exporting statistics reports into Matlab and generating figures.