ML Defender achieves F1=0.9985 on CTU-13 Neris botnet detection with a dual fast-detector plus random forest model, outperforming Suricata (zero alerts) and Zeek (F1=0.042) in a three-paradigm comparison.
Reflections on trusting trust.Communications of the ACM, 27(8):761–763
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.CR 1years
2026 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
ML Defender (aRGus NDR): An Open-Source Embedded ML NIDS for Botnet and Anomalous Traffic Detection in Resource-Constrained Organizations
ML Defender achieves F1=0.9985 on CTU-13 Neris botnet detection with a dual fast-detector plus random forest model, outperforming Suricata (zero alerts) and Zeek (F1=0.042) in a three-paradigm comparison.