Skip to main content

Table 3 Sequential activity mining results

From: B-CAT: a model for detecting botnet attacks using deep attack behavior analysis on network traffic flows

Dataset source

Scenario/sensor

Sequential activity detected total

Sequence length

Min

Max

Average

CTU-13

1

5167

1

7420

8

2

1927

1

2814

11

3

26,789

1

3

1

4

596

1

1304

4

5

183

1

275

5

6

1651

1

199

3

7

17

1

21

4

8

1833

1

833

3

9

27,944

1

15,112

7

10

163

1

8018

652

11

14

1

4144

583

12

1687

1

70

1

13

2179

1

21,407

18

NCC-1

1

1865

1

1610

12

2

936

1

1526

26

3

19

36

1000

105

4

624

1

1994

18

5

300

1

1000

63

6

643

1

1000

9

7

17

119

1000

529

8

736

1

1047

19

9

15,854

1

3000

14

10

88

181

1819

682

11

12

1000

1000

1000

12

939

1

1000

10

13

853

1

1896

22

NCC-2

1

3637

1

4198

40

2

18,630

1

6887

20

3

18,687

1

5543

16