@article{1707, author = {1Abdulmuneem Bashaiwth, 1Basil AsSadhan, 2Jalal Al-Muhtadi, and 1,3Saleh Alshebeili}, title = {Efficient Detection of Real-World Botnets’ Command and Control Channels Traffic}, journal = {Progress in Computing Applications}, year = {2014}, volume = {3}, number = {2}, doi = {}, url = {}, abstract = {Botnets are a major security threat to today’s Internet. Therefore, the detection of botnets has become a central task for network administrators. In this paper, we study the detection of botnets by monitoring and analyzing the Command and Control (C2) channels communication traffic. We note that this detection approach is effective as it detects a botnet before it engages in any harmful activities. We analyze real network traffic captured at King Saud University network by exploiting the periodic behavior in C2 traffic. We use periodograms to study the periodic behavior, and apply Walker’s large sample test to detect whether the traffic has a significant periodic component or not, and, if it does, then it is bot traffic. We apply this test on two different days of KSU traffic. We show that the traffic in those days exhibit periodic behavior and report the source of that traffic as bot.}, }