2013
DOI: 10.1002/sec.800
|View full text |Cite
|
Sign up to set email alerts
|

Survey on network‐based botnet detection methods

Abstract: Botnets are an important security problem on the Internet. They continuously evolve their structure, protocols and attacks. This survey analyzes and compares the most important efforts carried out in a network‐based detection area. It accomplishes four tasks: first, the comparison of previous surveys and the proposal of four new dimensions to analyze their classification schemes; second, a new classification and comparison of network‐based botnet detection proposals, which includes the definition of 20 desired… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
49
0
2

Year Published

2014
2014
2022
2022

Publication Types

Select...
5
3
1

Relationship

1
8

Authors

Journals

citations
Cited by 80 publications
(51 citation statements)
references
References 35 publications
0
49
0
2
Order By: Relevance
“…We extract 8 features associated with each network trace. The features include frequency, duration, send and received bytes, send and received packages, protocol, port range 3 . Each network trace is represented by a feature vector.…”
Section: Features Extractionmentioning
confidence: 99%
See 1 more Smart Citation
“…We extract 8 features associated with each network trace. The features include frequency, duration, send and received bytes, send and received packages, protocol, port range 3 . Each network trace is represented by a feature vector.…”
Section: Features Extractionmentioning
confidence: 99%
“…Nowadays, machine learning is widely used in botnet detection system as a core component [1][2][3]. However, with financial motivation, attackers keep generating new variants and evolving their evasion schemes.…”
Section: Introductionmentioning
confidence: 99%
“…In a recent survey on network-based botnet detection methods by Garcia et al [7], the authors took an in-depth look at the most widely used and researched botnet detection tools available. In this review there was a discussion which highlighted the fact that bot detection mechanisms have different requirements than botnet detection mechanisms due to the difference in detecting one machine as opposed to a group of machines.…”
Section: Related Workmentioning
confidence: 99%
“…While there are a lot of methods to detect them [4], there is yet a need to improve their detection performance. Since most of these methods use a behavioral model of the botnet on their algorithms and since most of them focus on the behavior of their Command and Control channels (C&C), we believe that having a better model of the behavior of these channels may help to create better detection algorithms.…”
Section: Introductionmentioning
confidence: 99%