Research Article
Hybrid Botnet Detection Based on Host and Network Analysis
Table 7
List of selected artifacts for host monitor.
| Feature number | Behavior features |
| 1 | Creation of DLL or EXE in system directory | 2 | Creation of and set the value of AutoRun key in registry | 3 | Critical registry key modification | 4 | Active time of the bot process |
|
|