首页> 外文会议>IEEE International Conference on Communications >On advanced monitoring in resilient and unstructured P2P botnets
【24h】

On advanced monitoring in resilient and unstructured P2P botnets

机译:关于弹性和非结构化P2P僵尸网络中的高级监视

获取原文

摘要

Botnets are a serious threat to Internet-based services and end users. The recent paradigm shift from centralized to more sophisticated Peer-to-Peer (P2P)-based botnets introduces new challenges for security researchers. Centralized botnets can be easily monitored, and once their command and control server is identified, easily be taken down. However, P2P-based botnets are much more resilient against such attempts. To make it worse, botnets like P2P Zeus include additional countermeasures to make monitoring and crawling more difficult for the defenders. In this paper, we discuss in detail the problems of P2P botnet monitoring. As our main contribution, we introduce the Less Invasive Crawling Algorithm (LICA) for efficiently crawling unstructured P2P botnets and utilize only local information. We compare the performance of LICA with other known crawling methods such as Depth-first and Breadth-first search. This is achieved by simulating these methods on not only a real-world botnet dataset, but also on an unstructured P2P file sharing network dataset. Our analysis results indicate that LICA significantly outperforms the other known crawling methods.
机译:僵尸网络对基于Internet的服务和最终用户构成了严重威胁。最近从集中式到更复杂的基于对等(P2P)的僵尸网络的范式转变为安全研究人员带来了新的挑战。集中式僵尸网络可以很容易地受到监视,并且一旦识别出它们的命令和控制服务器,就可以轻松将其删除。但是,基于P2P的僵尸网络对于此类尝试的抵御能力更大。更糟糕的是,像P2P Zeus这样的僵尸网络还包括其他对策,使防御者难以进行监视和爬网。在本文中,我们详细讨论了P2P僵尸网络监控的问题。作为我们的主要贡献,我们引入了入侵较少的爬网算法(LICA),可以有效地爬网非结构化P2P僵尸网络,并且仅利用本地信息。我们将LICA与其他已知的爬网方法(例如深度优先和宽度优先搜索)的性能进行了比较。通过不仅在真实世界的僵尸网络数据集上而且在非结构化P2P文件共享网络数据集上模拟这些方法,可以实现这一点。我们的分析结果表明,LICA明显优于其他已知的爬网方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号