Research Article
Abnormal Behavior Detection to Identify Infected Systems Using the APChain Algorithm and Behavioral Profiling
Table 16
Experimental results for C&C channel detection according to the threshold value.
| Category | Accuracy | Precision | Recall | FP rate |
| Threshold A (0, 240) ≤ x ≥ 240, x=frequency | 0.0156 | 0.0006 | 1.0 | 0.9850 |
| Threshold B (30, 240) ≤ x ≥ 240 | 0.9998 | 0.8571 | 1.0 | 0.0001 |
| Threshold C (30, 720) ≤ x ≥ 720 | 0.9856 | 0.0428 | 1.0 | 0.0143 |
| Threshold D (90, 720) ≤ x ≥ 720 | 0.9854 | 0.0289 | 0.6667 | 0.0143 |
| Threshold E (0, ∞) ≤ x ≥ ∞ | 0.0006 | 0.0006 | 1.0 | 1.0 |
|
|