Peer-to-Peer Botnet Detection based on Bot Behaviour
Abstract
Peer-to-Peer (P2P) botnets are a significant threat to network security because of their distributed platform. The detection of these botnets becomes very difficult because of their decentralized nature and the situation worsens if an existing P2P network is exploited for botnetwork creation (parasite botnets). In this paper, we propose a two-tier detection framework to detect parasite P2P botnets. The approach can detect botnets in their waiting stage and without any requirement of bots’ signature. For detection of bots, we have considered two features: (i) long-living peers, search requests’ (ii) intensity and (iii) temporal correlated behaviour. The approach is able to detect bots from a monitored network with high detection accuracy. Keywords: peer-to-peer; botnets; botnet detection
Full Text:
PDFDOI: https://doi.org/10.26483/ijarcs.v8i3.2970
Refbacks
- There are currently no refbacks.
Copyright (c) 2017 International Journal of Advanced Research in Computer Science

