Challenges in Botnet Enumeration

Sven Dietrich
Stevens Institute of Technology

I will present the challenges encountered in analyzing a peer-to-peer (P2P) botnet, both from a passive and active measurement perspective. Both types of measurements occurred from multiple locations on the network and led to topology discovery, the understanding of the associated distributed denial of service attacks, and estimates of the botnet population over a period of 2+ years. I include some preliminary results from this study.

