首页 | 官方网站   微博 | 高级检索  
     

一种基于bot优先抽样的P2P botnet 在线检测技术
引用本文:李华波,胡谷雨,杨 云,赖海光.一种基于bot优先抽样的P2P botnet 在线检测技术[J].解放军理工大学学报,2013,0(2):139-144.
作者姓名:李华波  胡谷雨  杨 云  赖海光
作者单位:1.解放军理工大学 指挥信息系统学院,江苏 南京 210007; 2.北方电子设备研究所,北京 100191
基金项目:江苏省自然科学基金资助项目(BK2011115)
摘    要:僵尸网络利用高效灵活的一对多控制机制,为攻击者提供了储备、管理和使用网络攻击能力的基础架构和平台,已成为当前Internet最严重且持续增长的安全威胁之一。为满足在高速网络实时检测P2P僵尸网络的需求,提出了一种基于bot优先抽样的在线检测技术。该方法利用bot优先的分级算法和基于优先级的包抽样算法,使得检测系统能够高效利用计算资源,在整体抽样率有限条件下,优先对疑似P2P僵尸通信数据包进行抽样,并使用流信息重构技术和流簇分析技术对抽样包进行统计分析来发现P2P僵尸主机。实验结果表明,所提出的在线检测技术能够有效提高对疑似P2P僵尸网络流量亚群的包抽样率,具有良好的在线检测效率和P2P僵尸检测命中率。

关 键 词:僵尸网络  P2P  在线检测  抽样
收稿时间:2012-05-15
修稿时间:2012-05-15

Bot priority sampling based P2P botnet online detection technique
LI Huabo,HU Guyu,YANG Yun and LAI Haiguang.Bot priority sampling based P2P botnet online detection technique[J].Journal of PLA University of Science and Technology(Natural Science Edition),2013,0(2):139-144.
Authors:LI Huabo  HU Guyu  YANG Yun and LAI Haiguang
Affiliation:1.College of Command Information System, PLA Univ. of Sci. & Tech., Nanjing 210007,China; 2.The Institute of North Electronic Equipment,Beijing 100191,China
Abstract:Botnets pose a steady and growing threat to network security and have become one of the most significant threats to the Internet. Using highly efficient and flexible one to many control mechanisms, botnets provide a infrastructure of reserves, management and use of cyber attack capabilities. To meet the instant detection requirements of P2P botnets on high speed networks, a bot priority sampling based online detection technique was presented. In order to efficiently use as many as possible the limited computing resources and sample packets of suspicious P2P bots, a bot priority classification algorithm and a priority based sampling algorithm were proposed. Flow information recovering and flow cluster analyzing approaches were used to identify the suspicious P2P bots based on the sampled packets. The experimental evaluation results show that the proposed technique can increase the sampling rates packets from P2P botnets traffic subpopulations and has a good sampling efficiency and P2P bots detection hit rate.
Keywords:botnet  P2P  online detection  sampling
点击此处可从《解放军理工大学学报》浏览原始摘要信息
点击此处可从《解放军理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号