首页> 外文会议>IEEE Conference on Local Computer Networks >The Early Bird Gets the Botnet: A Markov Chain Based Early Warning System for Botnet Attacks
【24h】

The Early Bird Gets the Botnet: A Markov Chain Based Early Warning System for Botnet Attacks

机译:早起的鸟儿获得了僵尸网络:基于马尔可夫链的僵尸网络攻击预警系统

获取原文

摘要

Botnet threats include a plethora of possible attacks ranging from distributed denial of service (DDoS), to drive-by-download malware distribution and spam. While for over two decades, techniques have been proposed for either improving accuracy or speeding up the detection of attacks, much of the damage is done by the time attacks are contained. In this work we take a new direction which aims to predict forthcoming attacks (i.e. before they occur), providing early warnings to network administrators who can then prepare to contain them as soon as they manifest or simply quarantine hosts. Our approach is based on modelling the Botnet infection sequence as a Markov chain with the objective of identifying behaviour that is likely to lead to attacks. We present the results of applying a Markov model to real world Botnets' data, and show that with this approach we are successfully able to predict more than 98% of attacks from a variety of Botnet families with a very low false alarm rate.
机译:僵尸网络威胁包括从分布式拒绝服务(DDoS)到按下载下载的恶意软件分发和垃圾邮件等多种可能的攻击。尽管已经有二十多年的历史了,人们提出了提高准确性或加快攻击检测的技术,但大部分破坏是在遏制攻击时完成的。在这项工作中,我们采取了一个新的方向,旨在预测即将发生的攻击(即在它们发生之前),向网络管理员提供预警,然后网络管理员可以在它们出现或只是隔离主机后立即准备遏制它们。我们的方法基于将僵尸网络感染序列建模为马尔可夫链,目的是识别可能导致攻击的行为。我们介绍了将马尔可夫模型应用于现实世界僵尸网络数据的结果,并表明通过这种方法,我们可以成功地预测来自各种僵尸网络系列的98%以上的攻击,且误报率非常低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号