Chinese Journal of Network and Information Security ›› 2018, Vol. 4 ›› Issue (10): 31-38.doi: 10.11959/j.issn.2096-109x.2018078

• Papers • Previous Articles     Next Articles

Method of botnet network nodes detection base on communication similarity

Yuquan JIN1,2,Bin XIE1,Yi ZHU2   

  1. 1 Institute of Electronic Engineering in China Academy of Engineering Physics,Mianyang 621900,China
    2 Sichuan University,Chengdu 610065,China
  • Revised:2018-09-30 Online:2018-10-15 Published:2018-12-15


At present,the botnet detection method mostly relies on the analysis of the network communication activity or the communication content.The former carries on the statistical analysis to the characteristic of the data flow,does not involve the content in the data flow,has the strong superiority in the detection encryption type aspect,but the accuracy is low.The latter relies on the prior knowledge to examine,has the strong accuracy,but the generality of detection is low.The communication similarity was defined according to Jaccard similarity coefficient,and a method of calculating communication similarity based on user request DNS (domain name system) was proposed,which was used for botnet node detection based on network traffic.Finally,based on the spark framework,the experimental results show that the proposed method can be used in the detection of botnet nodes effectively.

Key words: botnet, similarity detection, DNS flow detection, network security

CLC Number: 

No Suggested Reading articles found!