检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]国防科学技术大学计算机学院,长沙410073 [2]国家计算机网络应急技术处理协调中心,北京100029
出 处:《计算机学报》2010年第1期45-54,共10页Chinese Journal of Computers
基 金:国家"八六三"高技术研究发展计划项目基金(2007AA010502;2007AA01Z474;2006AA01Z451)资助~~
摘 要:IRC僵尸网络(botnet)是攻击者通过IRC服务器构建命令与控制信道方式控制大量主机(bot)组成的网络.IRC僵尸网络中IRC服务器与bot连接具有很强的动态特性,为识别使用不同IRC服务器的同一僵尸网络,文中提取并比对僵尸网络的通信量特征、通信频率特征,建模估算bot重叠率,通过融合以上度量指标,提出了僵尸网络相似性度量模型.实验验证了模型的有效性,计算了其准确率,并分析了僵尸网络的迁移.IRC botnet can be regarded as a collection of compromised computers(called Zombie computers)running software under the command-and-control infrastructure constructed by the IRC servers.The connection between the botnet server and the bots are usually very dynamic.In order to describe a botnet at a finer granularity,the paper proposes a method that measures the similarity of botnets by extracting and comparing the metrics such as communication volumes,frequency,and the overlap rate of bots.A novel model for botnet similarity measuring is proposed by combining those metrics mentioned. Experiments are carried out for validation ses,the confidence of the accuracy is evaluated and shown, and the migration situation of are also discussed. purpobotnet
分 类 号:TP393[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.15