BOOK-CHAPTER

Detecting Botnet Traffic from a Single Host

Sebastián GarcíaAlejandro ZuninoMarcelo Campo

Year: 2015 Advances in information security, privacy, and ethics book series Pages: 426-446   Publisher: IGI Global

Abstract

The detection of bots and botnets in the network may be improved if the analysis is done on the traffic of one bot alone. While a botnet may be detected by correlating the behavior of several bots in a large amount of traffic, one bot alone can be detected by analyzing its unique trends in less traffic. The algorithms to differentiate the traffic of one bot from the normal traffic of one computer may take advantage of these differences. The authors propose to detect bots in the network by analyzing the relationships between flow features in a time window. The technique is based on the Expectation-Maximization clustering algorithm. To verify the method they designed test-beds and obtained a dataset of six different captures. The results are encouraging, showing a true positive error rate of 99.08% with a false positive error rate of 0.7%.

Keywords:
Botnet Computer science Host (biology) Cluster analysis Maximization Traffic analysis Data mining Word error rate Artificial intelligence Computer security The Internet Mathematics World Wide Web Mathematical optimization

Metrics

0
Cited By
0.00
FWCI (Field Weighted Citation Impact)
36
Refs
0.30
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Topics

Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing
Internet Traffic Analysis and Secure E-voting
Physical Sciences →  Computer Science →  Artificial Intelligence

Related Documents

JOURNAL ARTICLE

Detecting encrypted botnet traffic

Han ZhangChristos PapadopoulosDan Massey

Year: 2013 Vol: 5789 Pages: 163-168
JOURNAL ARTICLE

Detecting botnet by anomalous traffic

Chia-Mei ChenHsiao-Chung Lin

Journal:   Journal of Information Security and Applications Year: 2014 Vol: 21 Pages: 42-51
JOURNAL ARTICLE

Detecting Botnet based on Network Traffic

Nguyen Vuong Tuan Hiep

Journal:   International Journal of Advanced Trends in Computer Science and Engineering Year: 2020 Vol: 9 (3)Pages: 3010-3014
© 2026 ScienceGate Book Chapters — All rights reserved.