期刊文献+

大规模网络环境下僵尸网络检测研究 被引量:1

Research on Botnet Detection in Large-scale Network Environment
下载PDF
导出
摘要 互联网面临安全隐患,而僵尸网络是最严重的隐患之一。介绍了高速网络环境下数据获取与还原,总结了僵尸网络检测的组织架构,在此基础上设计了僵尸网络检测系统,完成了IRC/HTTP Bot程序检测。在阶段性检测算法基础上设计了僵尸程序检测算法。运用该算法捕获并分析了15天内的监测数据,验证了该系统的有效性。 The computer and the Internet have played an extremely important role in people's working life, but the Internet is still facing a lot of security risks, the botnet is one of the most serious dangers. For the current problems, a botnet detection system was proposed, for high-speed network environment, data acquisition and reduction were introduced. This paper summarizes the organizational structure of botnet detection. On this basis, we design a botnet detection system, which completes the detection of IRC/HTTP Bot program. A zombie program detection algorithm is designed on the basis of the proposed periodic detection algorithm. Using the algorithm to capture and analyze the monitoring data within 15 days, it is concluded that the botnet is still the most serious problem in the current network environment, and the validity of the system is verified.
作者 任斌 周亦敏 REN Bin ZHOU Yi-min(School of Optical-Electrical and Computer Engineering, University of Shanghai for Science and Technology , Shanghai 20009)
出处 《软件导刊》 2017年第10期189-191,共3页 Software Guide
关键词 僵尸网络 僵尸网络检测 IRC HTTP 网络安全 botnet botnet detection IRC HTTP network security
  • 相关文献

参考文献3

二级参考文献19

  • 1[1]Libnids. An implementation of an E-component of network intrusion detection system. http: //www. packetfactory.net/Proj ects/Libnids/
  • 2[2]Chesson G. UNIX Review,1987,5(9):70
  • 3[3]Goldberg M, Neufeld G. The raven protocol framework.Univ Tech Rep TR-92-15, British Columbia, Vancouver,BC, Canada: 1992
  • 4[4]Goldberg M, Neufeld G, Ito M. A parallel approach to OSI connection-oriented protocols. In: Proc 3rd IFIP Workshop Protocols for High-Speed Networks, Stockholm,Sweden: 1992. 225
  • 5[5]Jain N, Schwartz M, Bashkow T. Transport protocols processing at GBPS rates. In: Proc ACM SIGCOMM'90,Philadelphia, PA: 1990. 188
  • 6[6]Yates D, Nahum E, Kurose J, et al. Networking support for large scale multiprocessor servers. In: Proc SIGMETRICS'96, Philadelphia, PA: 1996. 116
  • 7[7]Bjorkman M,Gunningberg P. IEEE/ACM Transctions on Networking, 1998,6(3): 262
  • 8[8]tcpdump. Dump traffic on a network. http://www. tcpdump. org
  • 9[9]Wolfram Gloger's malloc homepage. http://www. malloc.de/en/
  • 10RUBINI A.等著 魏永明 骆刚 姜君译.LINUX设备驱动程序(第2版)[M].北京,中国电力出版社,2002..

共引文献79

同被引文献2

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部