Principal Component Analysis of Botnet Takeover

Hiroaki Kikuchi, Shuji Matsuo, Masato Terada
2011 Journal of Information Processing  
A botnet is a network of compromised computers infected with malware that is controlled remotely via public communications media. Many attempts at botnet detection have been made including heuristics analyses of traffic. In this study, we propose a new method for identifying independent botnets in the CCC Dataset 2009, the log of download servers observed by distributed honeypots, by applying the technique of Principal Component Analysis. Our main results include distinguishing four independent
more » ... ng four independent botnets when a year is divided into five phases.
doi:10.2197/ipsjjip.19.463 fatcat:iwwfjs3xtvbd7ezxyftv5k3kv4