期刊文献+

基于SVM的Fast—flux僵尸网络检测技术研究 被引量:7

Research on Fast-flux Botnet Detection Technology based on SVM
下载PDF
导出
摘要 近些年出现的采用Fast—flux技术的僵尸网络,给网络安全带来了极大的威胁。因此,有效检测Fast—flux僵尸网络就成为网络安全研究者关注的热点问题。目前的检测方法都存在误报率较高的问题。针对这个不足,通过对Fast—flux僵尸网络数据进行分析,选取Fast—flux僵尸网络的六个典型特征,提出了基于SVM的Fast—flux僵尸网络的检测方法。实验表明,基于SVM的Fast—flux僵尸网络检测方法明显地降低误报率。 In recent years, a new type ofbotnet, using fast-flux technology, brings great challenges to network security. So how to detect fast-flux botnet effectively has become a hot topic for network security researchers. The detection methods nowadays have the common shortage of high false alarming rate. In this paper, six common features of fast-flux hornet are selected by a long time of observation and a fast-flux hornet detection method based on SVM is proposed. Experiment shows that fast-flux botnet detection method based on SVM reduces the false-alarming rate significantly.
作者 康乐 李东 余翔湛 KANG Le, LI Dong, YU Xiangzhan (School of Computer Science & Technology, Harbin Institute of Technology, Harbin 150001, China)
出处 《智能计算机与应用》 2011年第1X期24-27,共4页 Intelligent Computer and Applications
基金 基金项目:973项目(2007CB311101),863项目(2010AA012504),自然科学基金(60903166).
关键词 僵尸网络 支持向量机 Fast—flux 域名系统 Botnet SVM Fast-flux DNS
  • 相关文献

参考文献12

  • 1CHOI H,,LEE H,KIM H.BotGAD:detecting botnets by cap-turing group activities in network traffic. The Fourth Inter-national ICST Conference on Communication System software a-nd middleware . 2009
  • 2XU Shouhuai.Analyzing DNS Activities of Bot Processes. 4th International Conference on Malicious and Unwanted Soft-ware . 2009
  • 3TAKEMORI K.Detection of NS Resource Record Based DNSQuery Request Packet Traffic and SSH Dictionary Attack Ac-tivity. Intelligent Networks and Intelligent Systems . 2009
  • 4ROMAA D A L,KUBOTA S.DNS Based Spam Bots Detectionin a University. Intelligent Networks and Intelligent System-s . 2008
  • 5NAZARIO J,HOLZ T.As the Net Churns:Fast-Flux BotnetObservations. 3rd International Malicious and Unwanted Soft-ware . 2008
  • 6ZHOU Chenfeng,KARUNASEKERA C,PENG S T.A Self-He-alinng,Self-Protecting Collaborative Intrusion Detection Arch-itecture to Trace-Back Fast-Flux Phishing Domains. IEEENOMS Workshops . 2008
  • 7CAGLAYAN A,TOOTHAKER M,DRAPEAU D,et al.Real-time detection of fast flux service networks. Conference ForHomeland Security,Cybersecurity Applications and Technology . 2009
  • 8CAGLAYAN A,TOOTHAKER M,DRAPEAU D,et al.Beha-vioral Patterns of Fast Flux Service Networks. Cyber Secu-rity and Information Intelligence Track.Hawaii International C-onference on System Sciences . 2010
  • 9WU Jiayan,ZHANG Liwei,QU Sheng,et al.A comparativestudy for fast-flux service networks detection. NetworkedComputing and Advanced Information Management.Sixth Inte-rnational Conference . 2010
  • 10http://www.abuse.ch/ .

同被引文献29

引证文献7

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部