首页> 外文会议>2013 Eighth International Conference on Broadband, Wireless Computing, Communication and Applications >Empirical Evidence for Non-equilibrium Behaviors within Peer-to-Peer Structured Botnets
【24h】

Empirical Evidence for Non-equilibrium Behaviors within Peer-to-Peer Structured Botnets

机译:对等结构化僵尸网络中非平衡行为的经验证据

获取原文
获取原文并翻译 | 示例

摘要

Although we have become adept at taking-down individual botnets, the global botnet threat has remained largely unabated, particularly if one considers the more recent generation of peer-to-peer (P2P) structured botnets. A potential formal explanation for this dichotomy is that P2P botnets simply fail to behave as statistically equilibrium systems, (i.e., as systems possessing singular statistical steady-states). Equilibrium assumptions have been commonly applied in the construction of botnet defenses, but these assumption have gone untested. This work shows empirically via standard Monte Carlo packet-level simulations that well studied Kademlia P2P botnet protocol can easily produce both statistically non-stationary and non-ergodic behaviors once the Internet routing processes are modeled. Moreover, it is shown that by re-tuning a botnet's run-time parameters a botmaster can make the botnet behave as a non-stationary process from the defender's perspective. More formally, this work provides empirical evidence that network level botnet detection features need not be measure invariant as has generally been presupposed.
机译:尽管我们已经擅长于删除单个僵尸网络,但全球僵尸网络的威胁仍然没有减轻,尤其是当人们考虑使用更新一代的点对点(P2P)结构的僵尸网络时。这种二分法的潜在形式上的解释是,P2P僵尸网络根本无法充当统计平衡系统(即拥有奇异统计稳态的系统)。僵尸网络防御的构造通常采用平衡假设,但这些假设未经检验。这项工作通过标准的蒙特卡罗数据包级仿真经验性地表明,对Internet路由过程进行建模后,对Kademlia P2P僵尸网络协议进行深入研究就可以轻松地产生统计上不稳定的和非遍历行为。此外,从防御者的角度来看,它表明,通过重新调整僵尸网络的运行时参数,僵尸主机可以使僵尸网络的行为像一个非平稳过程。更正式地说,这项工作提供了经验证据,证明网络级僵尸网络检测功能不需要像通常所假设的那样测量不变性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号