The Detection of Intrusion Through P2P Botnet Based on the Analysis of Successful Connection Rate and Average Packet

LIU Jian-bo

Index Terms

Intrusion;P2P botnet; successful connection rate ;flow; average packet; clustering


Through the research on the mechanism of the P2P botnet, this paper proposes a algorithm of intrusion detection by P2P botnet based on the analysis of successful connection rate. According to the flow, it gets a data collection including three vectors, such as source IP, destination IP and package size, does dynamic analysis of the successful connection rate and average packet. Through the comparison with the methods between the traditional network and normal P2P,this paper provides intuitive figures in which we could locate the position of intrusion by P2P botnet accurately, therefore the algorithm could provide the gist for detecting the intrusion in time.

LIU Jian-bo,"The Detection of Intrusion Through P2P Botnet Based on the Analysis of Successful Connection Rate and Average Packet", IJEM, vol.2, no.1, pp.22-26, 2012.


