Journal of Information Processing
Online ISSN : 1882-6652
ISSN-L : 1882-6652
Principal Component Analysis of Botnet Takeover
Hiroaki KikuchiShuji MatsuoMasato Terada
Author information
JOURNAL FREE ACCESS

2011 Volume 19 Pages 463-472

Details
Abstract
A botnet is a network of compromised computers infected with malware that is controlled remotely via public communications media. Many attempts at botnet detection have been made including heuristics analyses of traffic. In this study, we propose a new method for identifying independent botnets in the CCC Dataset 2009, the log of download servers observed by distributed honeypots, by applying the technique of Principal Component Analysis. Our main results include distinguishing four independent botnets when a year is divided into five phases.
Content from these authors
© 2011 by the Information Processing Society of Japan
Previous article Next article
feedback
Top