首页> 外文会议>International Conference on Computer Communications and Networks >Botnet Detection Based on Passive Network Traffic Monitoring
【24h】

Botnet Detection Based on Passive Network Traffic Monitoring

机译:基于被动网络流量监控的僵尸网络检测

获取原文

摘要

Botnets are collections of compromised computers which are remotely controlled by its originator under a common Command-and-Control (C&C) infrastructure. Most of the existing botnet detection approaches concentrate only on particular botnet command and control (C&C) protocols (e.g., IRC, HTTP) and structures (e.g., centralized), and can become ineffective as botnets change their structure and C&C techniques. In this paper, we proposed a new general detection framework which currently focuses on P2P based botnets. This proposed framework is based on our definition of botnets. We define a botnet as a group of bots that will perform similar communication and malicious activity patterns within the same botnet. In our proposed detection framework, we monitor a group of host that demonstrate similar communication patterns in one step and also performing malicious activities in another step and finding common hosts on them. The point that distinguishes our proposed detection framework from many other similar works is that there is no need for prior knowledge of botnets such as botnet signature.
机译:僵尸网络是受损计算机的集合,这些计算机通过其发起者在公共指令和控制(C&C)基础架构下远程控制。大多数现有的僵尸网络检测方法仅集中在特定的僵尸网络命令和控制(C&C)协议(例如,IRC,HTTP)和结构(例如,集中),并且随着僵尸网络改变其结构和C&C技术,可以变得无效。在本文中,我们提出了一种新的一般检测框架,目前专注于基于P2P的僵尸网络。这一提议的框架是基于我们对僵尸网络的定义。我们将僵尸网络定义为一组机器人,该组是在同一僵尸网络中执行类似的通信和恶意活动模式。在我们提出的检测框架中,我们监控一组主机,该主机在一步中展示类似的通信模式,并且还在另一个步骤中执行恶意活动,并在它们上寻找公共主机。与许多其他类似作品不同我们提出的检测框架区分的重点是,不需要先前了解僵尸网络签名等僵尸网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号