Departmental Papers (CIS)

Date of this Version


Document Type

Conference Paper


Aviv, A. & Haeberlen, A., Challenges in Experimenting with Botnet Detection Systems, 4th USENIX Workshop on Cyber Security Experimentation and Test (CSET'11), Aug. 2011


In this paper, we examine the challenges faced when evaluating botnet detection systems. Many of these challenges stem from difficulties in obtaining and sharing diverse sets of real network traces, as well as determining a botnet ground truth in such traces. On the one hand, there are good reasons why network traces should not be shared freely, such as privacy concerns, but on the other hand, the resulting data scarcity complicates quantitative comparisons to other work and conducting independently repeatable experiments. These challenges are similar to those faced by researchers studying large-scale distributed systems only a few years ago, and researchers were able to overcome many of the challenges by collaborating to create a global testbed, namely PlanetLab. We speculate that a similar system for botnet detection research could help overcome the challenges in this domain, and we briefly discuss the associated research directions.



Date Posted: 19 July 2012