Skip to main content

Table 6 Botnet characteristic detection results

From: B-CAT: a model for detecting botnet attacks using deep attack behavior analysis on network traffic flows

Dataset source

Scenario/sensor

Average similarity value comparation with every characteristic (%)

Predicted

Sporadic

Periodic

Simultaneous

CTU-13

1

96.68

13.45

13.31

Sporadic

2

98.59

9.21

10.29

Sporadic

3

99.97

50.02

50.01

Sporadic

4

95.54

20.84

19.79

Sporadic

5

99.18

18.68

16.67

Sporadic

6

94.46

32.36

35.60

Sporadic

7

100

23.03

28.07

Sporadic

8

98.17

34.79

31.80

Sporadic

9

97.95

14.70

14.37

Sporadic

10

100

0.14

0.14

Sporadic

11

100

0.11

0.11

Sporadic

12

99.34

61.23

63.48

Sporadic

13

98.98

5.76

5.45

Sporadic

NCC-1

1

10.57

94.92

34.40

Periodic

2

6.33

96.93

39.94

Periodic

3

0

100

81.58

Periodic

4

7.41

95.96

40.40

Periodic

5

2.03

98.21

52.94

Periodic

6

13.36

93.15

23.84

Periodic

7

0

100

59.33

Periodic

8

7.31

96.82

64.23

Periodic

9

10.03

95.17

89.41

Periodic

10

0.01

99.80

95.93

Periodic

11

0

100

16.67

Periodic

12

54.17

66.04

76.27

Simultaneous

13

7.63

96.25

22.63

Periodic

NCC-2

1

3.47

66.13

97.86

Simultaneous

2

7.13

65.53

95.43

Simultaneous

3

8.88

79.03

94.05

Simultaneous