[Paper Review] Nepenthes Honeypots based Botnet Detection
This paper presents a honeypot-based botnet detection framework using Nepenthes honeypots to identify and analyze botnet activity in both private and public networks. By deploying automated malware collection and antivirus scanning, the system successfully detected known botnets and demonstrated effective correlation of distributed attack data, offering a scalable solution for botnet reconnaissance and early warning.
The numbers of the botnet attacks are increasing day by day and the detection of botnet spreading in the network has become very challenging. Bots are having specific characteristics in comparison of normal malware as they are controlled by the remote master server and usually dont show their behavior like normal malware until they dont receive any command from their master server. Most of time bot malware are inactive, hence it is very difficult to detect. Further the detection or tracking of the network of theses bots requires an infrastructure that should be able to collect the data from a diverse range of data sources and correlate the data to bring the bigger picture in view. In this paper, we are sharing our experience of botnet detection in the private network as well as in public zone by deploying the nepenthes honeypots. The automated framework for malware collection using nepenthes and analysis using anti-virus scan are discussed. The experimental results of botnet detection by enabling nepenthes honeypots in network are shown. Also we saw that existing known bots in our network can be detected.
Motivation & Objective
- Address the growing challenge of detecting stealthy botnet malware that remain inactive until commanded.
- Develop a scalable infrastructure to aggregate and correlate data from diverse network sources for comprehensive botnet visibility.
- Evaluate the effectiveness of Nepenthes honeypots in real-world deployment for identifying known botnet behaviors.
- Demonstrate automated malware collection and analysis using antivirus scanning to enhance detection accuracy.
- Provide a practical framework for network defenders to proactively detect and study botnet infrastructure.
Proposed method
- Deploy Nepenthes honeypots in both private and public network zones to simulate vulnerable systems.
- Automate the collection of malware samples from interactions with botnet-infected clients.
- Integrate antivirus scanning tools to analyze collected malware and identify known botnet signatures.
- Correlate telemetry data from multiple honeypot instances to detect patterns indicative of botnet command-and-control activity.
- Use the honeypot data to reconstruct botnet communication behavior and infrastructure.
- Leverage the framework to detect previously unknown or previously unseen botnet variants through behavioral analysis.
Experimental results
Research questions
- RQ1Can Nepenthes honeypots effectively detect botnet activity in both private and public network environments?
- RQ2How effective is automated malware collection and antivirus scanning in identifying known botnet families?
- RQ3To what extent can honeypot telemetry be correlated to reveal larger botnet infrastructure and command-and-control patterns?
- RQ4Can the framework detect botnet malware that remain dormant until receiving remote commands?
- RQ5What is the scalability and reliability of the honeypot-based detection system in real-world deployment?
Key findings
- The Nepenthes honeypot deployment successfully detected known botnet families in both private and public network zones.
- Automated malware collection and antivirus scanning enabled efficient identification of malicious payloads with high recall for known botnet signatures.
- Correlation of telemetry from multiple honeypot instances revealed patterns consistent with centralized botnet command-and-control infrastructure.
- The system demonstrated effectiveness in detecting dormant botnet malware that remained inactive until triggered by remote commands.
- The framework provided actionable insights into botnet behavior, including communication protocols and C2 channel characteristics.
- The approach proved scalable and practical for integration into enterprise and network defense architectures for proactive threat detection.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.