首页> 外文会议>Future Networks, 2010. ICFN '10 >Behavioural Correlation for Detecting P2P Bots
【24h】

Behavioural Correlation for Detecting P2P Bots

机译:检测P2P机器人的行为相关性

获取原文

摘要

In the past few years, IRC bots, malicious programs which are remotely controlled by attackers through IRC servers, have become a major threat to the Internet and for users. These bots can be used in different malicious ways such as issuing distributed denial of services attacks to shut down other networks and services, keystrokes logging, spamming, traffic sniffing cause serious disruption on networks and users. New bots use peer to peer (P2P) protocols start to appear as the upcoming threat to Internet security due to the fact that P2P bots do not have a centralized point to shutdown or trace back, thus making the detection of P2P bots is a real challenge. In response to these threats, we present an algorithm to detect an individual P2P bot running on a system by correlating its activities. Our evaluation shows that correlating different activities generated by P2P bots within a specified time period can detect these kind of bots.
机译:在过去的几年中,IRC僵尸程序是由攻击者通过IRC服务器进行远程控制的恶意程序,已成为对Internet和用户的主要威胁。这些漫游器可以以各种恶意方式使用,例如发出分布式拒绝服务攻击以关闭其他网络和服务,击键记录,垃圾邮件,流量嗅探会严重破坏网络和用户。由于P2P僵尸程序没有集中的关闭或追溯点,因此使用对等(P2P)协议的新僵尸程序开始出现,即将成为对Internet安全的威胁。因此,检测P2P僵尸程序是一个真正的挑战。 。针对这些威胁,我们提出了一种算法,可以通过关联其活动来检测在系统上运行的单个P2P机器人。我们的评估表明,将P2P僵尸程序在指定时间段内生成的不同活动相关联可以检测到此类僵尸程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号