{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T22:15:37Z","timestamp":1771539337670,"version":"3.50.1"},"reference-count":49,"publisher":"Emerald","issue":"1","license":[{"start":{"date-parts":[[2011,4,5]],"date-time":"2011-04-05T00:00:00Z","timestamp":1301961600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,4,5]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>A botnet is a network of computers on the internet infected with software robots (or bots). There are numerous botnets, and some of them control millions of computers. Cyber criminals use botnets to launch spam e\u2010mails and denial of service attacks; and commit click fraud and data theft. Governments use botnets for political purposes or to wage cyber warfare. The purpose of this paper is to review the botnet threats and the responses to the botnet threats.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The paper describes how botnets are created and operated. Then, the paper discusses botnets in terms of architecture, attacking behaviors, communication protocols, observable botnet activities, rally mechanisms, and evasion techniques. Finally, the paper reviews state\u2010of\u2010the\u2010art techniques for detecting and counteracting botnets, and also legal responses to botnet threats.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Botnets have become the platform for many online threats such as spam, denial of service attacks, phishing, data thefts, and online frauds. Security researchers must develop technology to detect and take down botnets, and governments must develop capacity to crack down on botmasters and botnets. Individual computer owners must diligently take measures to keep their computers from becoming members of botnets.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The paper provides a review of current status of botnets and a summary of up\u2010to\u2010date responses to botnets in both technical and legal aspects, which can be used as a stepping stone for further research.<\/jats:p><\/jats:sec>","DOI":"10.1108\/17440081111125635","type":"journal-article","created":{"date-parts":[[2011,4,9]],"date-time":"2011-04-09T07:16:52Z","timestamp":1302333412000},"page":"6-17","source":"Crossref","is-referenced-by-count":10,"title":["Botnets: threats and responses"],"prefix":"10.1108","volume":"7","author":[{"given":"Ok\u2010Ran","family":"Jeong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chulyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Won","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jungmin","family":"So","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022022020135443100_b1","unstructured":"APEC (2008), \u201cGuide on policy and technical approaches against botnet\u201d, available at: www.mtc.gob.pe\/portal\/apectel38\/spsg\/08_tel38_spsg_012rev1_botnet\u2010guide\u2010version6\u20104.pdf."},{"key":"key2022022020135443100_b2","unstructured":"B\u00e4cher, P., Holz, T., K\u00f6tter, M. and Wicherski, G. (2005), \u201cKnow your enemy: tracking botnets\u201d, available at: http:\/\/old.honeynet.org\/papers\/bots."},{"key":"key2022022020135443100_b3","doi-asserted-by":"crossref","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Xu, Y. and Karir, M. (2009), \u201cA survey of botnet technology and defenses\u201d, Proceedings of the Cyber Security Applications and Technology Conference for Homeland Security, Washington, DC, USA, pp. 299\u2010304.","DOI":"10.1109\/CATCH.2009.40"},{"key":"key2022022020135443100_b4","unstructured":"Barroso, D. (2007), \u201cBotnets \u2013 the silent threat\u201d, European Network and Information Security Agency (ENISA) Position Paper, Vol. 3, pp. 1\u20109."},{"key":"key2022022020135443100_b5","doi-asserted-by":"crossref","unstructured":"Bhagwan, R., Savage, S. and Voelke, G.M. (2003), \u201cUnderstanding availability\u201d, Proceedings of the 2nd International Workshop on P2P, Berkeley, CA, USA, pp. 256\u201067.","DOI":"10.1007\/978-3-540-45172-3_24"},{"key":"key2022022020135443100_b6","unstructured":"Binkley, J.R. and Singh, S. (2006), \u201cAn algorithm for anomaly\u2010based botnet detection\u201d, Proceedings of Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI \u201906), Portland, OR, USA, p. 7."},{"key":"key2022022020135443100_b7","unstructured":"Brodsky, A. and Brodsky, D. (2007), \u201cA distributed content independent method for spam detection\u201d, Proceedings of the First Workshop on Topics in Understanding Botnets (HotBots \u201907), Cambridge, MA, USA, p. 3."},{"key":"key2022022020135443100_b8","unstructured":"CERT (2005), \u201cMalware tunneling in IPv6\u201d, available at: www.us\u2010cert\u2010gov\/reading_room\/IPv6Malware\u2010Tunneling.pdf."},{"key":"key2022022020135443100_b9","doi-asserted-by":"crossref","unstructured":"Choi, H., Lee, H., Lee, H. and Kim, H. (2007), \u201cBotnet detection by monitoring group activities in DNS traffic\u201d, Proceedings of 7th IEEE International Conference on Computer and Information Technology (CIT \u201907), Aizu\u2010Wakamatsu, Japan, pp. 715\u201020.","DOI":"10.1109\/CIT.2007.90"},{"key":"key2022022020135443100_b10","unstructured":"Cooke, E., Jahanian, F. and McPherson, D. (2005), \u201cThe zombie roundup: Understanding, detecting, and disrupting botnets\u201d, Proceedings of Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI \u201905), San Jose, CA, USA, p. 6."},{"key":"key2022022020135443100_b11","unstructured":"Dagon, D. (2005), \u201cBotnet detection and response, the network is the infection\u201d, Proceedings of OARC Workshop, Santa Clara, CA, USA."},{"key":"key2022022020135443100_b12","unstructured":"Diocyde (2009), \u201cSmashing the Mega\u2010d\/Ozdok botnet in 24 hours\u201d, available at: http:\/\/blog.fireeye.com\/research\/2009\/11\/smashing\u2010the\u2010ozdok.html."},{"key":"key2022022020135443100_b13","unstructured":"Eltringham, S. (2007), \u201cUnlawful online conduct and applicable federal laws\u201d, available at: www.cybercrime.gov\/ccmanual\/appxa.pdf."},{"key":"key2022022020135443100_b14","unstructured":"Espiner, T. (2010), \u201cDutch police take down Bredolab botnet\u201d, available at: www.zdnet.co.uk\/news\/security\u2010threats\/2010\/10\/26\/dutch\u2010police\u2010take\u2010down\u2010bredolab\u2010botnet\u201040090649\/ (accessed October 26, 2010)."},{"key":"key2022022020135443100_b15","unstructured":"Fisher, D. (2009), \u201cHow to take down a botnet\u201d, available at: http:\/\/threatpost.com\/en_us\/blogs\/how\u2010take\u2010down\u2010botnet\u2010110909."},{"key":"key2022022020135443100_b16","unstructured":"Fortune 500 (2008), \u201cFortune 500\u201d, available at: http:\/\/money.cnn.com\/magazines\/fortune\/fortune500\/2008\/full_list\/."},{"key":"key2022022020135443100_b17","doi-asserted-by":"crossref","unstructured":"Freiling, F., Holz, T. and Wicherski, G. (2005), \u201cBotnet tracking \u2013 exploring a root cause methodology\u201d, Lecture Notes in Computer Science (LNCS), Vol. 3679, pp. 319\u201035.","DOI":"10.1007\/11555827_19"},{"key":"key2022022020135443100_b18","unstructured":"Goebel, J. and Holz, T. (2007), \u201cRishi: identify bot contaminated hosts by IRC nickname evaluation\u201d, Proceedings of First Workshop on Hot Topics in Understanding Botnets (HotBots \u201907), Cambridge, MA, USA, p. 8."},{"key":"key2022022020135443100_b21","unstructured":"Gu, G.,, Zhang, J., and Lee, W. (2008a), \u201cBotSniffer: detecting botnet command and control channels in network traffic\u201d, Proceedings of the 15th Annual Network & Distributed System Security Symposium (NDSS), San Diego, CA, USA."},{"key":"key2022022020135443100_b20","unstructured":"Gu, G., Perdisci, R., Zhang, J. and Lee, W. (2008b), \u201cBotMiner: clustering analysis of network traffic for protocol\u2010 and structure\u2010independent botnet detection\u201d, Proceedings of the 17th USENIX Security Symposium (Security \u201908), San Jose, CA, USA, pp. 139\u201054."},{"key":"key2022022020135443100_b19","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Frog, M. and Lee, W. (2007), \u201cBotHunter: detecting malware infection through IDS\u2010driven dialog correlation\u201d, Proceedings of the 16th USENIX Security Symposium (Security \u201907), Boston, MA, USA, Article No. 12."},{"key":"key2022022020135443100_b22","unstructured":"Holz, T., Steiner, M., Dahl, F., Biersack, E.W. and Freiling, F. (2008), \u201cMeasurements and mitigation of peer\u2010to\u2010peer\u2010based botnets: a case study on stormworm\u201d, Proceedings of the 1st USENIX Workshop on Large\u2010scale Exploits and Emergent Threats, San Francisco, CA, USA, Article No. 9."},{"key":"key2022022020135443100_b23","unstructured":"Honeynet Project (2005), \u201cKnow your enemy: GenII Honeynets \u2013 easier to deploy, harder to detect, safer to maintain\u201d, available at: http:\/\/old.honeynet.org\/papers\/gen2."},{"key":"key2022022020135443100_b24","unstructured":"Karasaridis, A., Rexroad, B. and Hoeflin, D. (2007), \u201cWide\u2010scale botnet detection and characterization\u201d, Proceedings of First Workshop on Hot Topics in Understanding Botnets (HotBots \u201907), Cambridge, MA, USA, p. 7."},{"key":"key2022022020135443100_b25","doi-asserted-by":"crossref","unstructured":"Kim, W., Jeong, O.R., Kim, C.Y. and So, J. (2010), \u201cOn botnets\u201d, Proceedings of iiWAS 2010, Paris, France, pp. 3\u20108.","DOI":"10.1145\/1967486.1967488"},{"key":"key2022022020135443100_b26","doi-asserted-by":"crossref","unstructured":"Lie, J., Xiao, Y., Ghaboosi, K., Deng, H. and Zhang, J. (2009), \u201cBotnet: classification, attacks, detection, tracing and preventive measures\u201d, EURASIP Journal on Wireless Communications and Networking, p. 11 (Article ID 692654).","DOI":"10.1155\/2009\/692654"},{"key":"key2022022020135443100_b29","doi-asserted-by":"crossref","unstructured":"McCarty, B. (2003), \u201cBotnets: big and bigger\u201d, IEEE Security & Privacy, Vol. 1 No. 4, pp. 87\u201090.","DOI":"10.1109\/MSECP.2003.1219079"},{"key":"key2022022020135443100_b30","unstructured":"McMillan, R. (2010), \u201cSpanish police take down massive Mariposa botnet\u201d, PCWorld, available at: www.pcworld.com\/businesscenter\/article\/190634\/spanish_police_take_down_massive_mariposa_botnet.html."},{"key":"key2022022020135443100_b27","doi-asserted-by":"crossref","unstructured":"Masud, M.M., Al\u2010khateeb, T., Khan, L., Thuraisingham, B. and Hamlen, K.W. (2008), \u201cFlow\u2010based identification of botnet traffic by mining multiple log file\u201d, Proceedings of the International Conference on Distributed Frameworks & Applications (DFMA), Penang, Malaysia, pp. 200\u20106.","DOI":"10.1109\/ICDFMA.2008.4784437"},{"key":"key2022022020135443100_b28","doi-asserted-by":"crossref","unstructured":"Maymounkov, P. and Maxieres, D. (2002), \u201cKademlia: a peer\u2010to\u2010peer information system based on the XOR metric\u201d, Proceedings of IPTPS, Cambridge, MA, USA, pp. 53\u201065.","DOI":"10.1007\/3-540-45748-8_5"},{"key":"key2022022020135443100_b31","unstructured":"MessageLabs (2010), MessageLabs Intelligence: 2010 Annual Security Report, available at: www.messagelabs.com\/mlireport\/MessageLabsIntelligence_2010_Annual_Report_FINAL.pdf."},{"key":"key2022022020135443100_b32","unstructured":"Ollman, G. (2009), \u201cBotnet communication topologies\u201d, White Paper, Damballa."},{"key":"key2022022020135443100_b33","unstructured":"Oudot, L., and Holz, T. (2004), \u201cDefeating honeypots: network issues, Part 2\u201d, available at: www.symantec.com\/connect\/articles\/defeating\u2010honeypots\u2010network\u2010issues\u2010part\u20102."},{"key":"key2022022020135443100_b34","unstructured":"Ramachandran, N.F.A. and Dagon, D. (2006), \u201cRevealing botnet membership using DNSBL counter\u2010intelligence\u201d, Proceedings of the 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet (SRUTI \u201906), San Jose, CA, USA, pp. 49\u201054."},{"key":"key2022022020135443100_b35","unstructured":"Schonewille, A., and van Helmond, D.J. (2006), \u201cThe domain name service as an IDS\u201d, Master's Project, University of Amsterdam, Amsterdam, available at: http:\/\/staff.science.uva.nl\/\u223cdelaat\/snb\u20102005\u20102006\/p12\/report.pdf."},{"key":"key2022022020135443100_b36","unstructured":"SecureWorks (2004), \u201cPhatbot trojan analysis\u201d, available at: www.secureworks.com\/research\/threats\/phatbot\/?threat=phatbot."},{"key":"key2022022020135443100_b37","unstructured":"Send\u2010Safe (2006), \u201cSend\u2010Safe honeypot hunter\u201d, available at: www.send\u2010safe.com\/honeypot\u2010hunter.html."},{"key":"key2022022020135443100_b38","doi-asserted-by":"crossref","unstructured":"Spitzner, L. (2003), \u201cThe honeynet project: trapping the hackers\u201d, IEEE Security and Privacy, Vol. 1 No. 2, pp. 15\u201023.","DOI":"10.1109\/MSECP.2003.1193207"},{"key":"key2022022020135443100_b39","doi-asserted-by":"crossref","unstructured":"Sroufe, P., Phithakkitnukoon, S., Dantu, R. and Cangussu, J. (2009), \u201cEmail shape analysis for spam botnet detection\u201d, Proceedings of the 6th IEEE Consumer Communications and Networking Conference (CCNC \u201909), Las Vegas, NV, USA, pp. 1\u20102.","DOI":"10.1109\/CCNC.2009.4784781"},{"key":"key2022022020135443100_b40","unstructured":"Stankovic, S. and Simic, S. (2009), \u201cDefense strategies against modern botnets\u201d, International Journal of Computer Science and Information Security, Vol. 2 No. 1, pp. 11\u201017."},{"key":"key2022022020135443100_b42","doi-asserted-by":"crossref","unstructured":"Strayer, W., Lapsley, D., Walsh, B. and Livadas, C. (2008), \u201cBotnet detection based on network behavior\u201d, Advances in Information Security, Vol. 36, pp. 1\u201024.","DOI":"10.1007\/978-0-387-68768-1_1"},{"key":"key2022022020135443100_b43","unstructured":"Trend Micro (2006), \u201cTaxonomy of bonet threats\u201d, White Paper, Trend Micro."},{"key":"key2022022020135443100_b44","doi-asserted-by":"crossref","unstructured":"Wang, P., Aslam, B. and Zou, C. (2010), \u201cPeer\u2010to\u2010peer botnets\u201d, Handbook of Information and Communication Security, Springer, Berlin, pp. 335\u201050.","DOI":"10.1007\/978-3-642-04117-4_18"},{"key":"key2022022020135443100_b46","unstructured":"Wikipedia (2010a), \u201cConflicker\u201d, available at: http:\/\/en.wikipedia.org\/wiki\/Conficker."},{"key":"key2022022020135443100_b45","unstructured":"Wikipedia (2010b), \u201cMariposa botnet\u201d, available at: http:\/\/en.wikipedia.org\/wiki\/Mariposa_botnet."},{"key":"key2022022020135443100_b48","unstructured":"Wikipedia (2011a), \u201cBotnet\u201d, available at: http:\/\/en.wikipedia.org\/wiki\/Botnet."},{"key":"key2022022020135443100_b47","unstructured":"Wikipedia (2011b), \u201cStuxnet\u201d, available at: http:\/\/en.wikipedia.org\/wiki\/Stuxnet."},{"key":"key2022022020135443100_b49","doi-asserted-by":"crossref","unstructured":"Xie, Y., Yu, F., Achan, K., Panigrahy, R., Hulten, G. and Osipkov, I. (2008), \u201cSpamming botnets: signatures and characteristics\u201d, Proceedings of ACM SIGCOMM \u201908, Orlando, FL, USA, pp. 171\u201082.","DOI":"10.1145\/1402946.1402979"},{"key":"key2022022020135443100_frd1","doi-asserted-by":"crossref","unstructured":"Stone\u2010Gross, B., Cova, M., Cavallaro, L., Gilbert, B., Szydlowski, M., Kemmerer, R., Kruegel, C. and Vigna, G. (2009), \u201cYour botnet is my botnet: analysis of a botnet takeover\u201d, Proceedings of CCS \u201909, Chicago, IL, USA, pp. 635\u201047.","DOI":"10.1145\/1653662.1653738"}],"container-title":["International Journal of Web Information Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/17440081111125635","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/17440081111125635\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/17440081111125635\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:25:02Z","timestamp":1753403102000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ijwis\/article\/7\/1\/6-17\/164272"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,4,5]]},"references-count":49,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,4,5]]}},"alternative-id":["10.1108\/17440081111125635"],"URL":"https:\/\/doi.org\/10.1108\/17440081111125635","relation":{},"ISSN":["1744-0084"],"issn-type":[{"value":"1744-0084","type":"print"}],"subject":[],"published":{"date-parts":[[2011,4,5]]}}}