Botnet Detection Model Based on Sequential Analysis

FAN Yi-yan,WU Guo-rui,CHEN Jian-li,TANG Bo
DOI: https://doi.org/10.16208/j.issn1000-7024.2011.09.064
2011-01-01
Abstract:The contemporary IRC botnet detection methods are not suitable for botnet detection under infrequently command and control interactions.To detect small stealthy botnet,a botnet detection model based on sequential analysis is proposed,which is a complement to contemporary passive detection technologies.Several probe methods and detection algorithms are discussed considering response types of clients,and average round of detection is analyzed,only small portion of command and control interactions are observed to declare single or multiple IRC bot.The results show that botnet detection is completed in expected round under controlled false positive rate and false negative rate.
What problem does this paper attempt to address?