(Taxonomy is the practice and science of classification.)
Erlend Westbye
Rune Johan Borgli
Paper makes use of 4 different network models:
Paper differentiates between structured and unstructured P2P models and considers them special cases of scale free models and random graph models.
This is because the selected metrics concern only basic botnet properties and would not be sufficient to distinguish P2P from random and scale free networks.
Effectiveness - Efficiency - Robustness
Major Botnet Utilities | Key Metrics | Suggested Variables |
---|---|---|
Effectiveness | Giant portion | S |
Effectiveness (cont) | Average Available Bandwidth | B |
Efficiency | Diameter | |
Robustness | Local transitivity |
Average bandwidth
The series of all groups i
Average maximum bandwidth
Average normal bandwidth use
Probability of bot being in group i
average online hours per day
Botnet Efficiency
The average clustering coefficient gamma/ measures the number of triads divided by the maximal number of possible triads
The attacker inserts a large amount of invalid information into the index (found in P2P file sharing systems) to prevent users from finding the correct resource