期刊文献+

中小型局域网中P2P僵尸网络的检测

P2P BOTNET DETECTION IN MEDIUM AND SMALL LAN
下载PDF
导出
摘要 传统的僵尸网络大多是基于IRC协议的集中式结构,但越来越多的僵尸网络开始转向了分布式的P2P结构,针对IRC信道的检测方法已经不适用于新型的P2P僵尸网络。提出一种面向中小型局域网,根据流量统计特性和恶意攻击活动相结合的P2P僵尸网络检测方法。这种方法对采用随机端口,数据加密等新型手段的Botnets可以进行有效检测。 Traditional botnets are central structured and run on IRC protocol.Recently,however,more and more botnets have transformed into distributed P2P structure.Therefore the IRC channel detection method no longer works fine with new types of P2P botnets.The paper introduces a P2P botnet detection method oriented to medium and small LANs that combines both flux features and malicious attacking activities.The method can effectively detect botnets with new approaches like random port,data encryption and so forth.
出处 《计算机应用与软件》 CSCD 2011年第10期80-83,共4页 Computer Applications and Software
基金 教育部科技司项目(CNGI2008-092)
关键词 P2P 僵尸网络 恶意活动 P2P Botnet Malicious activity
  • 相关文献

参考文献5

  • 1诸葛建伟,韩心慧,周勇林,叶志远,邹维.僵尸网络研究[J].软件学报,2008,19(3):702-715. 被引量:157
  • 2Grizzard J B, Sharma V, Nunnery C, et al. Peer-to-peer botnets : Over- view and case study[ C ]//Proceedings of USENIX HotBots' 07,2007.
  • 3Porras P, Saidi H, Yegneswaran V. A Multi-perspective Analysis of the Storm ( Peacomm ) Worm [ R ]. Technical report, Computer Science Laboratory, SRI International, October 2007.
  • 4Holz T, Steiner M, Dahl F, et al. Measurements and mitigation of peer- to-peer-based botnets: A case study on storm worm [ C ]//Proceedings of the First USENIX Workshop on Large-Scale Exploits and Emergent Threats ( LEET' 08 ) , 2008.
  • 5Gu G,Perdisci R,Zhang J, et al. Botminer: Clustering analysis of network traffic for protocol-and structure-independent botnet detection [ C]//Security, 2008.

二级参考文献4

共引文献156

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部