Back to Search Start Over

P2P Botnet Detection Based on Nodes Correlation by the Mahalanobis Distance

Authors :
Zhixian Yang
Buhong Wang
Source :
Information, Vol 10, Iss 5, p 160 (2019)
Publication Year :
2019
Publisher :
MDPI AG, 2019.

Abstract

Botnets are a common and serious threat to the Internet. The search for the infected nodes of a P2P botnet is affected by the number of commonly connected nodes, with a lower detection accuracy rate for cases with fewer commonly connected nodes. However, this paper calculates the Mahalanobis distance—which can express correlations between data—between indirectly connected nodes through traffic with commonly connected nodes, and establishes a relationship evaluation model among nodes. An iterative algorithm is used to obtain the correlation coefficient between the nodes, and the threshold is set to detect P2P botnets. The experimental results show that this method can effectively detect P2P botnets with an accuracy of >85% when the correlation coefficient is high, even in cases with fewer commonly connected nodes.

Details

Language :
English
ISSN :
20782489
Volume :
10
Issue :
5
Database :
Directory of Open Access Journals
Journal :
Information
Publication Type :
Academic Journal
Accession number :
edsdoj.bbb7d6784d3a4e71b75e94c4bd8f3925
Document Type :
article
Full Text :
https://doi.org/10.3390/info10050160