Research Article

Hybrid Botnet Detection Based on Host and Network Analysis

Table 5

Monitored network failure types.

ProtocolDescription of the failure
Packet sentPacket received

TCPTCP SYNTCP reset
TCP SYNICMP unreachable
TCP SYNNo packet received for 120 seconds

UDPUDPICMP unreachable
UDPNo packet received for 120 seconds

DNSDNS queryA DNS server error code to the queried domain