Today bot and botnet become the primary platform for various types of attacks in the internet. Because of this reason, there are many types of detection mechanisms that are proposed to detect the bot activity. These detection mechanisms are based on common malware detection model. Most of the existing systems uses two types of models – misuse and anomaly based. In misuse detection model, the system detects the attacks based on known signatures where as, in anomaly detection model it is based on abnormal behaviour of the system. Both these methods have its own advantages and disadvantages.