Title
BotCloud: Detecting botnets using MapReduce
Abstract
Botnets are a major threat of the current Internet. Understanding the novel generation of botnets relying on peer-to-peer networks is crucial for mitigating this threat. Nowadays, botnet traffic is mixed with a huge volume of benign traffic due to almost ubiquitous high speed networks. Such networks can be monitored using IP flow records but their forensic analysis form the major computational bottleneck. We propose in this paper a distributed computing framework that leverages a host dependency model and an adapted PageRank [1] algorithm. We report experimental results from an open-source based Hadoop cluster [2] and highlight the performance benefits when using real network traces from an Internet operator.
Year
DOI
Venue
2011
10.1109/WIFS.2011.6123125
WIFS
Keywords
DocType
Citations 
internet operator,major threat,current internet,ip flow record,benign traffic,botnet traffic,major computational bottleneck,detecting botnets,forensic analysis form,hadoop cluster,distributed processing,internet,computer network security,distributed computing
Conference
7
PageRank 
References 
Authors
0.46
0
5
Name
Order
Citations
PageRank
Jerome Francois1574.39
Shaonan Wang2754.90
Walter Bronzi3353.28
Radu State462386.87
Thomas Engel553859.08