A botnet is a network of internet-connected compromised devices. Botnets can be used to perform a distributed denial-of-service attack (DDoS attack), steal data, send spam, among many other creative malicious uses. Botnets can cause absurd amounts of damage. For example, a quick search for the word botnet on Google shows that 3 days before the time of writing, the Electrum Botnet Stole $4.6 Million in cryptocurrencies. In this recipe, we build a classifier to detect botnet traffic.
The dataset used is a processed subset of a dataset called CTU-13, and consists of botnet traffic captured in Czechia, at the CTU University in 2011. The dataset is a large capture of real botnet traffic mixed with normal and background traffic.