首页> 外文期刊>IEEE intelligent systems >Using Behavioral Similarity for Botnet Command-and-Control Discovery
【24h】

Using Behavioral Similarity for Botnet Command-and-Control Discovery

机译:使用行为相似性进行僵尸网络命令与控制发现

获取原文
获取原文并翻译 | 示例
       

摘要

Malware authors and operators typically collaborate to achieve the optimal profit. They also frequently change their behavior and resources to avoid detection. The authors propose a social similarity metrics that exploits these relationships to improve the effectiveness and stability of the threat propagation algorithm typically used to discover malicious collaboration. Furthermore, they propose behavioral modeling as a way to group similarly behaving servers, enabling extension of the ground truth that's so expensive to obtain in the field of network security. The authors also show that seeding the threat propagation algorithm from a set of coherently behaving servers (instead of from a single known malicious server identified by threat intelligence) makes the algorithm far more effective and significantly more robust, without compromising the precision of findings.
机译:恶意软件作者和运营商通常会合作以实现最佳收益。他们还经常更改其行为和资源以避免被发现。作者提出了一种社会相似性度量标准,该度量标准利用这些关系来提高通常用于发现恶意协作的威胁传播算法的有效性和稳定性。此外,他们提出将行为建模作为将行为相似的服务器进行分组的一种方式,从而实现对基础事实的扩展,而这在网络安全领域非常昂贵。这组作者还表明,从一组行为一致的服务器(而不是从由威胁情报识别的单个已知恶意服务器)中播种威胁传播算法,可以使该算法更加有效且更加健壮,而不会影响发现的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号