Research Article

Towards Accurate Node-Based Detection of P2P Botnets

Table 4

Features for flow-based detection comparison.


SrcIpFlow source IP address
SrcPortFlow source port address
DstIpFlow destination IP address
DstPortFlow destination port address
ProtocolTransport layer protocol or “mixed”
APLAverage payload packet length for time interval
PVVariance of payload packet length for time interval
PXNumber of packets exchanged for time interval
PPSNumber of packets exchanged per second in time interval
FPSThe size of the first packet in the flow
TBPThe average time between packets in time interval
NRThe number of reconnections for a flow
FPHNumber of flows from this address over the total number of flows generated per hour