The application relates to a method for discovering associated nodes of a springboard node. By analyzing the flow data of the springboard node in a
botnet, nodes with highly similar behaviors are discovered from the nodes connected to the springboard node, thereby discovering multiple associated nodes belonging to the same
botnet, positioning the C&C
server node possibly at the upper level, and providing help for subsequent
trace analysis, discovery and prevention of
botnet threats. The application can extract important features representing the behaviors of network nodes through analysis of network flow data, input the features into a well-constructed program after pretreatment, complete the discovery of nodes with similar behaviors, and output the results. By drawing a
flow curve of the communication between highly suspicious nodes and the springboard node and visually displaying the
flow curve, the upper and lower control relationship of the suspicious IP pair is further verified, and the discovery of associated nodes of the same botnet and
attack prevention are realized.