Recognition of P2P Bots Control Behavior

CHEN Hao,LI Zhi-tang,WANG Bin-bin,LI Dong
2011-01-01
Abstract:Compared to traditional centralized-based bots,P2P-based bots are more concealable and robust due to the distributed control mechanism.In this paper,we make a deep analysis and study on control behavior of P2P bots.First,we describe the concept of control flow similarity and quantitate it appropriately,secondly,we implement Pearson hypothesis testing algorithm to identify P2P bots control flows,and finally,we use automatic classification technique to make a second determination.Experiments show that the proposed method can effectively recognize P2P bots control behavior in campus with relatively low false positive.
What problem does this paper attempt to address?