Research Article

Hybrid Botnet Detection Based on Host and Network Analysis

Table 7

List of selected artifacts for host monitor.

Feature numberBehavior features

1Creation of DLL or EXE in system directory
2Creation of and set the value of AutoRun key in registry
3Critical registry key modification
4Active time of the bot process