Research Article

Towards Accurate Node-Based Detection of P2P Botnets

Table 2

Features for node-based analysis.

FeatureDescription

(1) NodeComputer address for transmitting information
(2) NPNumber of protocols used for time interval
(3) NFNumber of flows used for time interval
(4) NPSNumber of packets sent for time interval
(5) ALPS Average length of packets sent
(6) RNPRatio of number of packets sent to number of packets received for time interval
(7) RLPRatio of average sending packets length to average receiving packets length for time interval