Peer-to-Peer BotNet Traffic Analysis and Detection
- Authors
- Han, Dongseok; Han, Kyoung Soo; Kang, Boojoong; Han, Hwansoo; Im, Eul Gyu
- Issue Date
- Apr-2012
- Keywords
- Botnet detection; Network Security; Peer-to-Peer (P2P) Botnet; Traffic Analysis
- Citation
- Information, v.15, no.4, pp 1605 - 1624
- Pages
- 20
- Indexed
- SCIE
SCOPUS
- Journal Title
- Information
- Volume
- 15
- Number
- 4
- Start Page
- 1605
- End Page
- 1624
- URI
- https://scholarworks.bwise.kr/hanyang/handle/2021.sw.hanyang/165965
- ISSN
- 1344-8994
1344-8994
- Abstract
- One of the most serious threats against the Internet is attacks from botnets. The botnet amplifies the intensity of attacks through the cooperation of compromised hosts. Recently, some botnets have evolved into a decentralized structure like peer-to-peer (P2P) network. Without fixed C&C servers, P2P botnets are difficult to detect. In this paper, we proposed a multi-step P2P botnet detection system based on botnets' probing characteristics. The first step uses entropy of information theory to detect the compromised hosts with great performance, and the second step (duplication ratio) concentrates on decreasing false positives. The experiment results show better false positive rate than a previous system.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - 서울 공과대학 > 서울 컴퓨터소프트웨어학부 > 1. Journal Articles

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.