【24h】

A Framework for Understanding Botnets

机译:理解僵尸网络的框架

获取原文

摘要

Botnets have become a severe threat to the cyberspace. However, existing studies are typically conducted in an ad hoc fashion, by demonstrating specific analysis on captured bot programs or bot communication mechanisms so as to suggest means to counter them. Although such studies are important, another perhaps even more important problem that is largely left unaddressed is: How should we build a unified framework that can help us understand botnets in a systematic fashion? In this paper we make a first step towards the goal by presenting a framework, which especially suggests a general architecture that could be coupled with certain advanced techniques that have not been exploited in existing botnets. The framework also suggests a set of attributes that can be used to measure and compare botnets. Moreover, the dynamic nature of botnets (e.g., a victim machine may be powered-off during some time intervals) implies that a botnet, and thus its attributes, are stochastic in nature. This means that a meaningful comparison between botnet attributes should be based on the concept of stochastic order.
机译:僵尸网络已成为网络空间的严重威胁。然而,通过对捕获的机器人计划或机器人通信机制进行具体分析,通常以临时方式进行现有研究,以便建议对抗它们的意义。虽然这些研究很重要,但另一个也许更重要的问题,这在很大程度上留下了未解决的是:我们应该如何构建一个统一的框架,可以帮助我们以系统时尚了解僵尸网络?在本文中,我们通过呈现一个框架来实现目标的第一步,这尤其建议一种可以与现有僵尸网络中未被利用的某些先进技术耦合的一般架构。该框架还建议了一组可用于测量和比较僵尸网络的属性。此外,僵尸网络(例如,在某些时间间隔中可能断电)的动态性质意味着僵尸网络,因此其属性是随机性的。这意味着僵尸网络属性之间的有意义的比较应基于随机顺序的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号