检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:尹涛[1,2] 李世淙 庹宇鹏[1,2] 张永铮[1,2]
机构地区:[1]中国科学院信息工程研究所,北京100093 [2]中国科学院大学,北京100049 [3]国家计算机应急技术处理协调中心,北京100029
出 处:《通信学报》2017年第1期97-105,共9页Journal on Communications
基 金:国家自然科学基金资助项目(No.61572496);国家高技术研究发展计划("863"计划)基金资助项目(No.2013AA014703;No.2012AA012801)~~
摘 要:为打击僵尸网络,保障网络空间安全,提出一种新型的具备强抗毁性的社交僵尸网络(DR-SNbot),并给出了针对性的防御方法。DR-SNbot基于社交网络搭建命令与控制服务器(C&C-Server,command and control server),每个C&C-Server对应一个不同的伪随机昵称,并利用信息隐藏技术将命令隐藏在日志中发布,进而提出一种新型的命令与控制信道。当C&C-Server不同比例地失效时,DR-SNbot会发出不同等级的预警,通知攻击者构建新的C&C-Server,并自动修复C&C通信以保障其强抗毁性。在实验环境中,即使当前C&C-Server全部失效,DR-SNbot仍能在短期内修复C&C通信,将控制率维持在100%。最后,基于伪随机僵尸昵称与合法昵称在词法特征上的差异性,提出一种僵尸昵称检测方法,可有效检测社交僵尸网络利用自定义算法批量生成的伪随机僵尸昵称。实验结果表明,该方法召回率达到93%,准确率达到96.88%。To defeat botnets and ensure cyberspace security, a novel social network-based botnet with strong de- stroy-resistance (DR-SNbot), as well as its corresponding countermeasure, was proposed. DR-SNbot constructed command and control servers (C&C-Servers) based on social network. Each C&C-Server corresponded to a unique pseudo-random nickname. The botmaster issues commanded by hiding them in diaries using information hiding techniques, and then a novel C&C channel was established. When different proportions of C&C-Servers were invalid, DR-SNbot would send out different levels of alarms to inform attackers to construct new C&C-Servers. Then, DR-SNbot could automatically repair C&C com- munication to ensure its strong destroy-resistance. Under the experimental settings, DR-SNbot could resume the C&C com- munication in a short period of time to keep 100% of the control rate even if all the current C&C-Servers were invalid. Fi- nally, a botnet nickname detecting method was proposed based on the difference of lexical features of legal nicknames and pseudo-random nicknames. Experimental results show that the proposed method can effectively (precision: 96.88%, recall: 93%) detect pseudo-random nicknames generated by social network-based botnets with customized algorithms.
关 键 词:网络安全 社交网络 僵尸网络 命令与控制信道 防御策略
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.15.164.218