Botnet C&C Traffic and Flow Lifespans Using Survival Analysis
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F17%3APU123171" target="_blank" >RIV/00216305:26220/17:PU123171 - isvavai.cz</a>
Result on the web
<a href="http://ijates.org/index.php/ijates/article/view/205/138" target="_blank" >http://ijates.org/index.php/ijates/article/view/205/138</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.11601/ijates.v6i1.205" target="_blank" >10.11601/ijates.v6i1.205</a>
Alternative languages
Result language
angličtina
Original language name
Botnet C&C Traffic and Flow Lifespans Using Survival Analysis
Original language description
This paper addresses the issue of detecting unwanted traffic in data networks, namely the detection of botnet networks. In this paper, we focused on a time behavioral analysis, more specifically said – lifespans of a simulated botnet network traffic, collected and discovered from NetFlow messages, and also of real botnet communication of a malware. As a method we chose survival analysis and for rigorous testing of differences Mantel–Cox test. Lifespans of those referred traffics are discovered and calculated by lifelines using Python language. Based on our research we have figured out a possibility to distinguish the individual lifespans of C&C communications that are identical to each other by using survival projection curves, although it occurred in a different time course.
Czech name
—
Czech description
—
Classification
Type
J<sub>ost</sub> - Miscellaneous article in a specialist periodical
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/LO1401" target="_blank" >LO1401: Interdisciplinary Research of Wireless Technologies</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)<br>S - Specificky vyzkum na vysokych skolach
Others
Publication year
2017
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Name of the periodical
International Journal of Advances in Telecommunications, Electrotechnics, Signals and Systems
ISSN
1805-5443
e-ISSN
—
Volume of the periodical
6
Issue of the periodical within the volume
1
Country of publishing house
CZ - CZECH REPUBLIC
Number of pages
7
Pages from-to
38-44
UT code for WoS article
—
EID of the result in the Scopus database
—