Skip to main content

Table 4 Repetitive sequential traffic analysis results

From: B-CAT: a model for detecting botnet attacks using deep attack behavior analysis on network traffic flows

Dataset source

Scenario/sensor

Sequential activity total (after repetitive analysis)

Sequence length

Reduction (%)

Min

Max

Average

CTU-13

1

379

1

7420

72

92.65

2

106

1

2814

161

94.56

3

8

1

3

2

99.97

4

15

1

1304

105

97.47

5

39

1

275

19

79.03

6

26

1

199

58

98.42

7

7

1

21

8

56.25

8

44

1

833

33

97.59

9

1349

1

15,112

105

95.19

10

70

1

8018

1518

55.97

11

14

1

4144

583

0

12

43

1

70

8

97.45

13

106

1

21,407

328

95.14

NCC-1

1

146

1

1610

139

92.18

2

101

2

1526

222

89.46

3

15

36

1000

120

54.55

4

25

1

1994

404

96.01

5

57

7

1000

324

81.00

6

13

10

1000

396

98.00

7

16

119

1000

555

5.88

8

46

8

1047

277

93.75

9

1064

1

3000

184

93.32

10

88

181

1819

682

0

11

12

1000

1000

1000

0

12

37

5

1000

192

96.06

13

110

2

1896

159

87.31

NCC-2

1

395

1

4198

352

89.32

2

1257

1

6887

263

93.32

3

1178

1

5543

221

93.74