摘要
针对现有僵尸网络检测体系结构中协同功能的不足,提出一个层次协同模型,能够在信息、特性以及决策3个级别上进行信息共享与配合联动。基于该模型,提出一个僵尸网络协同检测体系结构——Bot_CODA,并设计了一个新型的特性提取模块,能够从多种数据中提取僵尸网络的内在特性。通过典型案例分析,表明Bot_CODA能够有效提高检测精度,增强检测能力。
Towards the deficiencies of collaborative functions in existing botnet detection architectures, a hierarchical collaborative model was proposed.The model shares information and cooperates in the three levels of information, fea-ture, and decision-making.On the basis of the proposed model, a botnet collaborative detection architecture(Bot_CODA) was proposed.With a novel feature extraction module, the architecture was able to extract the intrinsic features of botnet from a variety of data sets.The analysis of a representative case indicates that Bot_CODA improves detection accuracy and enhances detection capability.
出处
《通信学报》
EI
CSCD
北大核心
2009年第S1期15-22,共8页
Journal on Communications
基金
国家自然科学基金资助项目(90604006)
国家高技术研究发展计划("863"计划)基金资助项目(2008AA01A325)
国家重点基础研究发展计划("973"计划)基金资助项目(2009CB320503)~~
关键词
僵尸网络
层次协同模型
协同检测
体系结构
botnet
hierarchical collaborative model
collaborative detection
architecture