The Impact of the Observation Period for Detecting P2P Botnets on the Real Traffic Using BotCluster
In recent years, many studies on peer-to-peer (P2P) botnet detection have exhibited the excellent detection precision on synthetic logs collected from the testbed. However, most of them do not evaluate their effectiveness on real traffic. In this paper, we use our BotCluster to analyze real traffic...
Saved in:
Published in | New Trends in Computer Technologies and Applications Vol. 1013; pp. 82 - 92 |
---|---|
Main Authors | , , , , |
Format | Book Chapter |
Language | English |
Published |
Singapore
Springer Singapore Pte. Limited
2019
Springer Singapore |
Series | Communications in Computer and Information Science |
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | In recent years, many studies on peer-to-peer (P2P) botnet detection have exhibited the excellent detection precision on synthetic logs collected from the testbed. However, most of them do not evaluate their effectiveness on real traffic. In this paper, we use our BotCluster to analyze real traffic from April 2nd to April 15th, 2017, collected as Netflow format, with three time-scopes for detecting P2P botnet activities in two campuses (National Cheng Kung University (NCKU) and National Chung Cheng University (CCU)). Three time-scopes including single-day, three-day, and weekly observation period applied to the same traffic logs for revealing the influence of the observation period on P2P botnet detection. The experiments show that with the weekly observation period, the precision can increase 10% from 84% to 94% on the combined traffic logs of two campuses. |
---|---|
Bibliography: | The authors are grateful to the Ministry of Science and Technology, Taiwan for the financial support (This research funded by contract MOST-103-2221-E-006-144-MY3), National Center for High-Performance Computing, Taiwan for providing NetFlow log and VirusTotal for contributing the malicious IP checking. |
ISBN: | 9789811391897 9811391890 |
ISSN: | 1865-0929 1865-0937 |
DOI: | 10.1007/978-981-13-9190-3_8 |