Decision Tree based Detection of Botnet Flow

Cai Junzhao · Information Security and Communications Privacy · 2008

Botnet is one of the most serious security threats against information system. Detecting potential botnet flow in Internet is of great significance to the improvement of information system. The paper mainly explores the botnet based on IRCP, then analyzes the signatures between zombies and IRC servers and finally proposes a decision tree-based method for detecting botnet flow. The experiment proves that this method is feasible.

Read the paper · More papers on PaperTik