首页> 外文会议>2010 2nd International Conference on Education Technology and Computer >Detecting hiding malicious website using network traffic mining approach
【24h】

Detecting hiding malicious website using network traffic mining approach

机译:使用网络流量挖掘方法检测隐藏的恶意网站

获取原文

摘要

As the Internet continues to broaden its coverage worldwide, it has leaded to a spread of data searching, learning, entertaining, information exchanging, financing, commercial activities and so on via Internet. This tendency makes a serious situation that is the users of the Internet become attacking targets. There are many kind of network attack such as viruses, worms, and many other malicious codes were implemented to get the illegal benefits or for some particular purpose. In recent years, firewall techniques were being used to reject the anomaly Internet connections. And this has made the spreading of malwares gradually shifted from the traditional “Push-based” method to the “Pull-based” method. Therefore, how to prevent the illegitimate access from the attacker and maintaining the quality of service of network becomes an important issue of the network manager. In 2008, there was a new kind malware be found, that have some new features in comparison of the traditional malwares. Further, those codes can be self-updated by Internet. There are many malicious websites propose new version malicious code for the malware infect other computers under the same LAN to download and execute the malicious program automatically. These kinds of malicious websites cannot be easily detected in traditional firewall defense systems. This research proposed a malicious website detection system architecture and use spatial-temporal aggregating variables method to build a detection module from the NetFlow data. In our empirical evaluation results show this module has good performance to detect the malicious web sites. The results are helpful to improve the management of the large range network environment.
机译:随着Internet继续扩大其在世界范围内的覆盖范围,它已导致通过Internet进行数据搜索,学习,娱乐,信息交换,融资,商业活动等的传播。这种趋势使Internet用户成为攻击目标的严重局面。有许多类型的网络攻击,例如病毒,蠕虫和许多其他恶意代码,都是为了获得非法利益或出于某些特定目的而实施的。近年来,防火墙技术被用来拒绝异常的Internet连接。这使得恶意软件的传播逐渐从传统的“基于推送”的方法转变为“基于推送”的方法。因此,如何防止攻击者非法访问并保持网络服务质量成为网络管理者的重要课题。在2008年,发现了一种新型恶意软件,与传统恶意软件相比,它们具有一些新功能。此外,这些代码可以通过Internet进行自我更新。有许多恶意网站提出了新版本的恶意代码,供恶意软件感染同一LAN下的其他计算机,以自动下载并执行恶意程序。在传统的防火墙防御系统中,无法轻易检测到此类恶意网站。该研究提出了一种恶意的网站检测系统架构,并使用时空聚合变量方法从NetFlow数据构建检测模块。在我们的经验评估结果中表明,该模块具有很好的检测恶意网站的性能。结果有助于改善大型网络环境的管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号