首页> 外国专利> BOTNET DETECTION METHOD AND SYSTEM, AND STORAGE MEDIUM

BOTNET DETECTION METHOD AND SYSTEM, AND STORAGE MEDIUM

机译:僵尸网络检测方法和系统以及存储介质

摘要

Disclosed in the present invention are a botnet detection method and system, and a storage medium. The method comprises: obtaining original network traffic data in a monitored network and preprocessing the original network traffic data to obtain preprocessed network traffic data; constructing a terminal access relationship map on the basis of the preprocessed network traffic data; and mining an identifier list of terminals accessing a plurality of the same domain names from the terminal access relationship map to obtain a candidate node combination, and on the basis of a preset screening rule, screening the candidate node combination to obtain a botnet node detection result.
机译:本发明公开了一种僵尸网络检测方法,系统以及存储介质。该方法包括:获取被监控网络中的原始网络流量数据,并对原始网络流量数据进行预处理,得到预处理后的网络流量数据。根据预处理后的网络流量数据构建终端访问关系图;从终端访问关系图中挖掘出访问多个相同域名的终端的标识列表,以获取候选节点组合,并根据预设的筛选规则,筛选候选节点组合以获得僵尸网络节点检测结果。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号