Information and Media Technologies
Online ISSN : 1881-0896
ISSN-L : 1881-0896
Computer Networks and Broadcasting
Principal Component Analysis of Botnet Takeover
Hiroaki KikuchiShuji MatsuoMasato Terada
ジャーナル フリー

2011 年 6 巻 4 号 p. 1241-1250


A botnet is a network of compromised computers infected with malware that is controlled remotely via public communications media. Many attempts at botnet detection have been made including heuristics analyses of traffic. In this study, we propose a new method for identifying independent botnets in the CCC Dataset 2009, the log of download servers observed by distributed honeypots, by applying the technique of Principal Component Analysis. Our main results include distinguishing four independent botnets when a year is divided into five phases.

© 2011 Information Processing Society of Japan
前の記事 次の記事