Botnet Command and Control Detection via Network Flow Analysis — ICACNC 2026 | TechShield Publications
ICACNC 2026 · Conference Article

Botnet Command and Control Detection via Network Flow Analysis

Authors: Muhammad Luqman, Muhammad Waleed, Aoun Muhammad, Sana Tariq

Abstract

Botnet driven command and control channels have become the most tenacious attack vectors in advance networks. Detection tools using packet payloads or fixed signature databases are always playing catch up, especially since the widespread adoption of encrypted transport protocols. We explain a detection framework based on a directed edge attributed graph model of network traffic. The proposed scheme does not merge multiple flows between a pair of hosts into a single summary edge but instead retains each flow as a separate directed edge, each of which contains a complete feature vector including duration, byte counts, packet rates, and protocol indicators. A multi head Graph Neural Network with edge level attention is then used to distinguish command and control flows from legitimate traffic. Testing across the CTU-13 and ISOT corpora yielded a detection accuracy of 97.4 and an F1-score of 0.963, a margin of 3.8 percentage points above the strongest published comparison method. These results suggest that structural graph level cues embedded in botnet traffic contain information that cannot be exploited by per flow classifiers and that edge level preservation of flow attributes is a key ingredient in recovering that information.

Botnet Detection Command and Control Network Flow Analysis Graph Neural Network Edge-Attributed Graph Encrypted Traffic

Cite This Paper

M. Luqman, M. Waleed, A. Muhammad, and S. Tariq, “Botnet Command and Control Detection via Network Flow Analysis,” Proc. Int. Conf. on AI, Cybersecurity, and Next-Gen Computing (ICACNC 2026), The Government Sadiq College Women University Bahawalpur, Jul. 2026, doi: 10.67535/tsp.000003.012.