Research Article

Hybrid Botnet Detection Based on Host and Network Analysis

Table 3

List of selected artifacts for network monitor.

NumberArtifact

1Port source and destination
2IP source and destination
3Protocol (UDP or TCP)
4HTTP method (POST or GET)
5Total number of connections
6Number of failed connections
7First packet length
8Packet size
9Total number of packets
10Number of input small packets
11Number of output small packets