期刊文献+

Bot_CODA:僵尸网络协同检测体系结构 被引量:9

Bot_CODA:botnet collaborative detection architecture
下载PDF
导出
摘要 针对现有僵尸网络检测体系结构中协同功能的不足,提出一个层次协同模型,能够在信息、特性以及决策3个级别上进行信息共享与配合联动。基于该模型,提出一个僵尸网络协同检测体系结构——Bot_CODA,并设计了一个新型的特性提取模块,能够从多种数据中提取僵尸网络的内在特性。通过典型案例分析,表明Bot_CODA能够有效提高检测精度,增强检测能力。 Towards the deficiencies of collaborative functions in existing botnet detection architectures, a hierarchical collaborative model was proposed.The model shares information and cooperates in the three levels of information, fea-ture, and decision-making.On the basis of the proposed model, a botnet collaborative detection architecture(Bot_CODA) was proposed.With a novel feature extraction module, the architecture was able to extract the intrinsic features of botnet from a variety of data sets.The analysis of a representative case indicates that Bot_CODA improves detection accuracy and enhances detection capability.
出处 《通信学报》 EI CSCD 北大核心 2009年第S1期15-22,共8页 Journal on Communications
基金 国家自然科学基金资助项目(90604006) 国家高技术研究发展计划("863"计划)基金资助项目(2008AA01A325) 国家重点基础研究发展计划("973"计划)基金资助项目(2009CB320503)~~
关键词 僵尸网络 层次协同模型 协同检测 体系结构 botnet hierarchical collaborative model collaborative detection architecture
  • 相关文献

参考文献26

  • 1李瑞轩,胡劲纬,唐卓,卢正鼎.R^2BAC:基于风险的多自治域安全互操作模型[J].通信学报,2008,29(10):58-69. 被引量:7
  • 2诸葛建伟,韩心慧,周勇林,叶志远,邹维.僵尸网络研究[J].软件学报,2008,19(3):702-715. 被引量:157
  • 3程杰仁,殷建平,刘运,钟经伟.蜜罐及蜜网技术研究进展[J].计算机研究与发展,2008,45(z1):375-378. 被引量:35
  • 4王伟,曾国荪,刘涛.基于信任机制的协作系统形成与演化机制[J].通信学报,2006,27(11):31-35. 被引量:4
  • 5RAJAB M,,ZARFOSS J,MONROSE F.A multi-faceted approach to understanding the botnet phenomenon. Proceedings of ACM SIGCOMM/USENIX Internet Measurement Conference(IMC’06) . 2006
  • 6RAMACHANDRAN A,FEAMSTER N,DAGON D.Revealing Botnet membership using DNSBL counterintelligence. Proceedings of USENIX SRUTI’06 . 2006
  • 7BARFORD P,YEGNESWARAN V.An Inside Look at Botnets. . 2007
  • 8LEE J S,JEONG H C,PARK J H.The activity analysis of malicious http-based botnets using degree of periodic repeatability. Proceed-ings of2008International Conference on Security Technology,Sec-Tech2008 . 2008
  • 9CHOI H,LEE H.Botnet detection by monitoring group activities in DNS traffic. 7th IEEE International Conference on Computer and Information Technology . 2007
  • 10MATTHEW S,IGOR I.Detection of Peer-to-Peer Botnets. . 2008

二级参考文献66

共引文献197

同被引文献64

  • 1冯宗彬,时剑,黄国庆,李斌,刘军.一种新的P2P僵尸网络综合防御系统框架[J].军事通信技术,2010(1):66-71. 被引量:1
  • 2孙彦东,李东.僵尸网络综述[J].计算机应用,2006,26(7):1628-1630. 被引量:29
  • 3Zhang Z H, Kadobayashi Y. A holistic perspective on under- standing and breaking bomets: Challenges and countermeasures [J]. Journal of the National Institute of Information and Com- munications Technology, 2008,.55 (2-3):43-59.
  • 4Holz T, Steiner M, Dahl F, et al. Measurement and mitigation of peer-to-peer-based botnets: A case study on storm worm [C] //Proceeding of the Usenix Workshop on Large-Scale Ex- ploits and Emergent Threats, 2008: 1-9.
  • 5Zhang Z H,Kadobayashi Y.A holistic perspective on understanding and breaking botnets:challenges and countermeasures[J].Journal of the National Institute of Information and Communications Technology,2008,55 (2-3):43-59.
  • 6Holz T,Steiner M,Dahl F,et al.Measurement and mitigation of peer-to-peer-based botnets:a case study on storm worm[C]//Proceeding of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats,San Francisco,A pril 9,2008:1-9.
  • 7Leland W E,Taqqu M S,Willinger W,et al.On the self-similar nature of Ethernet traffic (extend version). IEEE ACM Transactions on Networking . 1994
  • 8Beran J,Sherman R,Taqqu M S,et al.Long-Range Dependence in Variable-Bit-Rate Video Traffic. IEEE Transactions on Communications . 1995
  • 9Grizzard J B,Sharma V,Nunnery C.Peer-to-Peer botnets: Overview and case study. Proc. of the 1st Workshop on Hot Topics in Understanding Botnets (HotBots 2007) . 2007
  • 10Sen S,Spatscheck O,Wang D,et al.Accurate,scalable in-network identification of p2p traffic using application signatures. Proceedings of the 13th International Conference on World Wide Web . 2004

引证文献9

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部