—Botnets are one of the most serious threats inthe Internet, and thus the effective detection of the botnetbecomes more and more important. In this paper, inspiredby IP tracing technology, we propose a novel botnet detectionmethod that can analyze the data packets, based on graphstructure clustering. This method analyzes the comprehensiveinformation of packages content and timestamp flow. Such acapability is achieved by improving the HEMST (HierarchicalEuclidean Minimum Spanning Tree) clustering algorithm. Itperforms a similarity matching process to find the sender ofeach cluster that is the controlled host in botnet. Experimentalresults show that the clustering correct rate can reach to 97%which demonstrates the effectiveness of our method, having abetter detection rate