首页> 外文OA文献 >Survey of Approaches and Features for the Identification of HTTP-Based Botnet Traffic
【2h】

Survey of Approaches and Features for the Identification of HTTP-Based Botnet Traffic

机译:基于HTTP的僵尸网络流量识别方法和功能概述

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Botnet use is on the rise, with a growing number of botmasters now switching to the HTTP-based C&C infrastructure. This offers them more stealth by allowing them to blend in with benign web traffic. Several works have been carried out aimed at characterising or detecting HTTP-based bots, many of which use network communication features as identifiers of botnet behaviour. In this paper, we present a survey of these approaches and the network features they use in order to highlight how botnet traffic is currently differentiated from normal traffic. We classify papers by traffic types, and provide a breakdown of features by protocol. In doing so, we hope to highlight the relationships between features at the application, transport and network layers.
机译:僵尸网络的使用正在增加,如今越来越多的僵尸网络管理员都转向基于HTTP的C&C基础架构。通过允许他们融入良性网络流量,这为他们提供了更多的隐身性。为了表征或检测基于HTTP的僵尸,已经进行了几项工作,其中许多使用网络通信功能作为僵尸网络行为的标识符。在本文中,我们对这些方法及其使用的网络功能进行了概述,以突出显示僵尸网络流量当前与正常流量之间的区别。我们按流量类型对论文进行分类,并按协议提供功能分类。在此过程中,我们希望强调应用程序,传输和网络层上功能之间的关系。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号