Related Experiment Video
Updated: Jan 13, 2026

The HoneyComb Paradigm for Research on Collective Human Behavior
Published on: January 19, 2019
Mapping Cyber Bot Behaviors: Understanding Payload Patterns in Honeypot Traffic
Shiyu Wang1, Cheng Tu1, Yunyi Zhang1,2
1College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China.
Cyber bot behaviors are mapped using TrafficPrint, a novel framework analyzing honeypot traffic payloads. This method extracts understandable patterns, revealing bot techniques and enabling better threat intelligence for cybersecurity.
Area of Science:
- Cybersecurity
- Network Security
- Machine Learning
Background:
- Cyber bots are prevalent, necessitating behavioral understanding for effective threat intelligence.
- Analyzing bot behaviors is challenging due to blended traffic payloads and evolving techniques.
- Honeypot sensors are crucial for capturing and analyzing bot traffic, but existing methods struggle with scale and diversity.
Purpose of the Study:
- To map cyber bot behaviors through payload pattern analysis in honeypot traffic.
- To develop an adaptable framework for analyzing diverse and large-scale bot payloads.
- To extract actionable threat intelligence from botnet communication patterns.
Main Methods:
- An 11-month measurement study of cyber bot behaviors using honeypot traffic.
- Development of TrafficPrint, a pattern extraction framework combining representation learning and clustering.
- Automatic extraction of human-understandable payload patterns without protocol-specific expertise.
Main Results:
- Collected 21.5 million application-layer payloads from globally distributed honeypot sensors.
- TrafficPrint extracted 296 patterns, automatically labeling 83.57% of unknown payloads from a small labeled dataset.
- Identified that 82% of bot patterns use semi-customized structures, 13% contain attribution markers, and bots employ evasion techniques.
Conclusions:
- TrafficPrint provides an adaptable and effective method for analyzing diverse honeypot payloads.
- Payload pattern analysis yields actionable threat intelligence, including bot customization, attribution markers, and evasion strategies.
- The findings enhance understanding of cyber bot ecosystems and inform cybersecurity defenses.
More Related Videos
11:18Closed-loop Neuro-robotic Experiments to Test Computational Properties of Neuronal Networks
Published on: March 2, 2015
09:09Radio Frequency Identification and Motion-sensitive Video Efficiently Automate Recording of Unrewarded Choice Behavior by Bumblebees
Published on: November 15, 2014
Related Concept Videos
Mass Analyzers: Overview
Mass Analyzers: Common Types
Bullying
Masking and Demasking Agents
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
Predator-Prey Interactions