摘要
P2P僵尸网络作为僵尸网络的高级形式具有分布式的结构,隐蔽性高,难于检测。基于僵尸网络的群体相似性,提出一种高效的P2P僵尸网络检测模型,能够将P2P僵尸程序流量从正常P2P文件共享程序流量中分离出来,具有较低的漏报率。
As advanced forms of botnets, P2P botnets employ decentralized substrates to gain stealthy and robustness and are difficult to detect. Proposes an efficient detection model based on group sim- ilarity in botnet which can separate botnet traffic from the background traffic of P2P file-shar- ing systems. Evaluation test shows the model has low false negative.
基金
安徽省高校自然科学研究项目(No.KJ2010B282
No.KJ2011B002)