Botnet Detection Method Based on Email Characteristic Match

范轶彦,邬国锐
DOI: https://doi.org/10.16208/j.issn1000-7024.2010.01.047
2010-01-01
Abstract:To decrease the complexity of Botnet characteristic extraction and improve the speed of classification,a Botnet detection method based on Email characteristic match,which relies on neither Email detailed contents nor traffic analysis is presented.Raw emails are abstracted and Email characteristics are generated.Hellinger distance is used to find the most match characteristic in Botnet Email characteristic repository,then the Botnet that send the spam is classified.Experimental results show that the proposed method gained good accuracy and high efficency if enough spam Emails are trained and Botnet Email characteristic repository is well generated.
What problem does this paper attempt to address?