Botnets are a type of malware that threatens network security. One of the frequently encountered botnet threats is SPAM. Many studies focus on building detection models to classify botnet and non-botnet activities in network flows. Thus, research that can specifically differentiate SPAM from botnet activities is quite challenging. This paper proposes a model to detect SPAM botnet activity in network traffic using two-stack decision tree algorithms. The first stack of the model focuses on classifying network traffic into botnet and normal activity classes. Meanwhile, the second stack classifies botnet activity into two types: spam botnets and non-spam botnets. The experimental results show that the proposed model performs better than the Decision Tree model, which detects three activity classes directly. Performance evaluation of the proposed model succeeded in getting a value of 97.19% accuracy, 97.13% precision, 97.19% recall. and 97.12%F'1-score.
Afiq Fawwaz HaidarDandy Pramana HostiadiTohari AhmadMuhammad Aidiel Rachman Putra
Saifuldeen H AbdulrahmanMohammad Salim