Real-time Botnets Activity Detection
Christophe Maudoux, Maham Fatima Kayani, Maroua Ghamri, Selma Boumerdassi · 2025
This article presents ${\text{DiNATrA}}{\mathcal{X}}$, an innovative methodology for the automated detection of network anomalies in heterogeneous environments (mobile, ethernet) or of different scopes (LAN, MAN, WAN). ${\text{DiNATrA}}{\mathcal{X}}$ is based on three main functional blocks: data collection and pre-processing, analysis by sectors of interest (SOI) and anomaly detection itself. This framework combines temporal modeling (Time Period, Slice & Slot) and digital signatures (DNAs) to identify and quantify variations in network behavior in order to extract any anomalies.Evaluated on two real data sets of completely different natures, namely CANCAN (mobile traffic from French operator Orange) and CTU-13 (botnet traffic), the ${\text{DiNATrA}}{\mathcal{X}}$ methodology demonstrated its effectiveness in detecting major events and the malicious activity of various botnets. These results underline the ability to detect anomalies linked to concrete events, such as outages, crowd movements or attacks, while adapting to the needs of the user attacks, by adapting to the different network topologies, ${\text{DiNATrA}}{\mathcal{X}}$ stands out for its generic, cyclic, fractal, and interpretable aspects, offering a robust reliable alternative to traditional methods based on raw network traffic analysis or statistical approaches.