Botnet detection and classification system

Botnets have been an issue for the past several years. Botnets have multiple capabilities to take over single computers or large networks thus, making them more dangerous than any other malware scattered around the Internet. A sign of a botnet infection is using the connection to send or receive dat...

Full description

Saved in:
Bibliographic Details
Main Authors: Aquino, Mark Christian P., Co, Martin Xavier T., Wong, Brian Edward A.
Format: text
Language:English
Published: Animo Repository 2011
Online Access:https://animorepository.dlsu.edu.ph/etd_bachelors/11858
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: De La Salle University
Language: English
Description
Summary:Botnets have been an issue for the past several years. Botnets have multiple capabilities to take over single computers or large networks thus, making them more dangerous than any other malware scattered around the Internet. A sign of a botnet infection is using the connection to send or receive data. Clustering of data to identify botnet activity plays an important role in preparation for future data analysis. Botnets are identified base on their behavior that deviates from a normal network activity. A set of attributes correspond to the behavior, in which it is clustered and analyzed to determine the family of a particular bot however, not all attributes present in the datasets are relevant in determining the botnet family given its behavior. In this paper, several datasets of malicious activity with different selected attributes crucial in correctly clustering botnets to their respective families. The viability of the Self-Organizing Map algorithm to classify botnets is verified during the course of the study.