基于通信特征提取和IP聚集的僵尸网络相似性度量模型  被引量:10

Modeling Botnets' Similarity Based on Communication Feature Extraction and IP Assembly

在线阅读下载全文

作  者:李润恒[1] 王明华[2] 贾焰[1] 

机构地区:[1]国防科学技术大学计算机学院,长沙410073 [2]国家计算机网络应急技术处理协调中心,北京100029

出  处:《计算机学报》2010年第1期45-54,共10页Chinese Journal of Computers

基  金:国家"八六三"高技术研究发展计划项目基金(2007AA010502;2007AA01Z474;2006AA01Z451)资助~~

摘  要:IRC僵尸网络(botnet)是攻击者通过IRC服务器构建命令与控制信道方式控制大量主机(bot)组成的网络.IRC僵尸网络中IRC服务器与bot连接具有很强的动态特性,为识别使用不同IRC服务器的同一僵尸网络,文中提取并比对僵尸网络的通信量特征、通信频率特征,建模估算bot重叠率,通过融合以上度量指标,提出了僵尸网络相似性度量模型.实验验证了模型的有效性,计算了其准确率,并分析了僵尸网络的迁移.IRC botnet can be regarded as a collection of compromised computers(called Zombie computers)running software under the command-and-control infrastructure constructed by the IRC servers.The connection between the botnet server and the bots are usually very dynamic.In order to describe a botnet at a finer granularity,the paper proposes a method that measures the similarity of botnets by extracting and comparing the metrics such as communication volumes,frequency,and the overlap rate of bots.A novel model for botnet similarity measuring is proposed by combining those metrics mentioned. Experiments are carried out for validation ses,the confidence of the accuracy is evaluated and shown, and the migration situation of are also discussed. purpobotnet

关 键 词:僵尸网络 通信 聚集 相似性度量 迁移 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象