僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾...僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾邮件发送等攻击目的。该文提出一种与僵尸网络结构和C&C协议无关,不需要分析数据包的特征负载的僵尸网络检测方法。该方法首先使用预过滤规则对捕获的流量进行过滤,去掉与僵尸网络无关的流量;其次对过滤后的流量属性进行统计;接着使用基于X-means聚类的两步聚类算法对C&C信道的流量属性进行分析与聚类,从而达到对僵尸网络检测的目的。实验证明,该方法高效准确地把僵尸网络流量与其他正常网络流量区分,达到从实际网络中检测僵尸网络的要求,并且具有较低的误判率。展开更多
The command and control(C2) is a decision-making process based on human cognition,which contains operational,physical,and human characteristics,so it takes on uncertainty and complexity.As a decision support approac...The command and control(C2) is a decision-making process based on human cognition,which contains operational,physical,and human characteristics,so it takes on uncertainty and complexity.As a decision support approach,Bayesian networks(BNs) provide a framework in which a decision is made by combining the experts' knowledge and the specific data.In addition,an expert system represented by human cognitive framework is adopted to express the real-time decision-making process of the decision maker.The combination of the Bayesian decision support and human cognitive framework in the C2 of a specific application field is modeled and executed by colored Petri nets(CPNs),and the consequences of execution manifest such combination can perfectly present the decision-making process in C2.展开更多
针对传统的手打拟票、手工记录以及电话下令的业务开展方式已成为操作效率提升的瓶颈,提出在调度指挥控制系统(dispatch command control system,DCCS)上设计调度操作指挥模块。将电话下令转变为网络交互;构建多种基于智能规则的自动成...针对传统的手打拟票、手工记录以及电话下令的业务开展方式已成为操作效率提升的瓶颈,提出在调度指挥控制系统(dispatch command control system,DCCS)上设计调度操作指挥模块。将电话下令转变为网络交互;构建多种基于智能规则的自动成票手段,取代传统的手打出票方式;操作完成后系统可自动记录设备状态信息并通知相关单位,实现调度操作全流程的网络化、信息化与智能化。模块上线运行结果表明,数据显示对调度操作效率的提升作用显著。展开更多
文摘僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾邮件发送等攻击目的。该文提出一种与僵尸网络结构和C&C协议无关,不需要分析数据包的特征负载的僵尸网络检测方法。该方法首先使用预过滤规则对捕获的流量进行过滤,去掉与僵尸网络无关的流量;其次对过滤后的流量属性进行统计;接着使用基于X-means聚类的两步聚类算法对C&C信道的流量属性进行分析与聚类,从而达到对僵尸网络检测的目的。实验证明,该方法高效准确地把僵尸网络流量与其他正常网络流量区分,达到从实际网络中检测僵尸网络的要求,并且具有较低的误判率。
基金supported by the National Natural Science Foundation of China (60874068)
文摘The command and control(C2) is a decision-making process based on human cognition,which contains operational,physical,and human characteristics,so it takes on uncertainty and complexity.As a decision support approach,Bayesian networks(BNs) provide a framework in which a decision is made by combining the experts' knowledge and the specific data.In addition,an expert system represented by human cognitive framework is adopted to express the real-time decision-making process of the decision maker.The combination of the Bayesian decision support and human cognitive framework in the C2 of a specific application field is modeled and executed by colored Petri nets(CPNs),and the consequences of execution manifest such combination can perfectly present the decision-making process in C2.
文摘针对传统的手打拟票、手工记录以及电话下令的业务开展方式已成为操作效率提升的瓶颈,提出在调度指挥控制系统(dispatch command control system,DCCS)上设计调度操作指挥模块。将电话下令转变为网络交互;构建多种基于智能规则的自动成票手段,取代传统的手打出票方式;操作完成后系统可自动记录设备状态信息并通知相关单位,实现调度操作全流程的网络化、信息化与智能化。模块上线运行结果表明,数据显示对调度操作效率的提升作用显著。