Online Detection for P2P Botnets Based on Host Behavioral Anomaly

YU Xiao-cong,DONG Xiao-mei,YU Ge
DOI: https://doi.org/10.3969/j.issn.1000-1220.2012.01.003
2012-01-01
Abstract:Botnets have become one of the most serious threats on the Internet.P2P-based Botnets have been developed a lot.The communication characteristics of P2P-based botnets bring great challenge for detection,which attract extensive attention of research communities.This paper proposed a new technique that can detect the P2P-based botnets activities in an online way.Firstly,we search the anomaly from network traffic by means of entropy analysis.Analyzing the behavioral anomaly of P2P-based botnets and distinguish the suspected P2P-based botnets hosts from normal network traffic by the hypothesis testing technique.Finally the botnet host identities would be confirmed by the similarity analysis of the communication pattern.The experimental evaluations show that this approach can achieve P2P-based botnets detection efficiently.
What problem does this paper attempt to address?