首页> 美国卫生研究院文献>Journal of Advanced Research >Fast Flux Watch: A mechanism for online detection of fast flux networks
【2h】

Fast Flux Watch: A mechanism for online detection of fast flux networks

机译:快速通量监视:在线检测快速通量网络的机制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Fast flux networks represent a special type of botnets that are used to provide highly available web services to a backend server, which usually hosts malicious content. Detection of fast flux networks continues to be a challenging issue because of the similar behavior between these networks and other legitimate infrastructures, such as CDNs and server farms. This paper proposes Fast Flux Watch (FF-Watch), a mechanism for online detection of fast flux agents. FF-Watch is envisioned to exist as a software agent at leaf routers that connect stub networks to the Internet. The core mechanism of FF-Watch is based on the inherent feature of fast flux networks: flux agents within stub networks take the role of relaying client requests to point-of-sale websites of spam campaigns. The main idea of FF-Watch is to correlate incoming TCP connection requests to flux agents within a stub network with outgoing TCP connection requests from the same agents to the point-of-sale website. Theoretical and traffic trace driven analysis shows that the proposed mechanism can be utilized to efficiently detect fast flux agents within a stub network.
机译:快速流量网络代表一种特殊的僵尸网络,该僵尸网络用于向通常承载恶意内容的后端服务器提供高可用性的Web服务。由于这些网络与其他合法基础设施(例如CDN和服务器场)之间的行为类似,因此快速通量网络的检测仍然是一个具有挑战性的问题。本文提出了快速通量监视(FF-Watch),一种在线检测快速通量剂的机制。 FF-Watch可以作为一种软件代理存在于将存根网络连接到Internet的叶路由器上。 FF-Watch的核心机制基于快速通量网络的固有特征:存根网络中的通量代理承担着将客户请求中继到垃圾邮件活动的销售点网站的作用。 FF-Watch的主要思想是将到存根网络中的通量代理的传入TCP连接请求与从相同代理到销售点网站的传出TCP连接请求相关联。理论和流量跟踪驱动的分析表明,所提出的机制可用于有效地检测存根网络中的快速助剂。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号