Distributed denial of service attacks take advantage of the inherent security vulnerabilities of tcp/ip protocol architecture. They are very effective,and can't efficiently defend,because what they generated are legal and data request. This paper describes the working principle of botnets. In the simulation environment,this paper analyzes a zombie tool which spreads through the IRC chat room. We can accurately determine the zombies、the controller and the IRC server according to the message characterstic. Moreover,this paper also analyzes the behavior of the zombie host. According to the behavior,we are able to judge whether the host is infected with the virus or not. In addition,this paper provides some ways to clear the Sdbot virus.
Control & Automation