Skip to Main Content
Aimed at the situation that it is difficult to detect the peer-to-peer (P2P) botnet, we provide a new method for detection based on the analysis network streams. Firstly, because the P2P streams reveal the characteristics of paroxysm and distribution, we can filtrate them with streams feature for our targets to analyze. Then, according to the cohesion in a P2P network, we can figure out the set of peers in a P2P network. Finally, by contrasting with the common botnet actions of the peers in a P2P network, we can distinguish a P2P-Botnet from the P2P networks. Besides all, plenty of experiments have been done and proved the efficiency and veracity of this method.