首页> 外文会议>2011 17th IEEE International Conference on Parallel and Distributed Systems >A Revised Ant Colony Optimization Scheme for Discovering Attack Paths of Botnet
【24h】

A Revised Ant Colony Optimization Scheme for Discovering Attack Paths of Botnet

机译:用于发现僵尸网络攻击路径的改进蚁群优化方案

获取原文

摘要

IP trace back technique is an effective method to find either the attack origin or command-and-control (C&C) server on the Internet. The traditional ACO (ant colony optimization) constantly converged to a local minimum solution easily such that the global most portable of the final solution might be missed. Accordingly, the present study proposes a modified ACS (ant colony system) scheme designated as ACS-IPTBK to solve the IP trace back problem, predict both the most probable attack path and the computational resources needed in botnets. The ability of the ants to search all feasible attack paths is enhanced by means of a global heuristics. A series of ns2 simulations are performed to investigate the minimum resources required to successfully reconstruct the attack path. The convergence time for attack paths of different routing distances were investigated using a random graph generator based on Waxman''s scheme. Overall, the results confirm that the proposed method provides an effective means of reconstructing the path between the attacker and the victim based on the incomplete routing information from the related ISPs.
机译:IP追溯技术是一种在Internet上找到攻击源或命令与控制(C&C)服务器的有效方法。传统的ACO(蚁群优化)一直很容易地收敛到本地最小解决方案,从而可能会错过最终解决方案的全球移植性最强的解决方案。因此,本研究提出了一种改进的ACS(蚁群系统)方案,称为ACS-IPTBK,以解决IP追溯问题,预测最可能的攻击路径和僵尸网络所需的计算资源。借助全局启发式方法,蚂蚁搜索所有可行攻击路径的能力得到了增强。执行了一系列ns2仿真,以研究成功重建攻击路径所需的最少资源。使用基于Waxman方案的随机图生成器,研究了不同路由距离的攻击路径的收敛时间。总体而言,结果证实了该方法为基于相关ISP的不完整路由信息提供了一种在攻击者与受害者之间重建路径的有效手段。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号