首页> 外国专利> METHOD AND APPARATUS OF ADAPTIVE AND FLEXIBLE INTRUSION DETECTION SYSTEM FOR P2P BOTNET

METHOD AND APPARATUS OF ADAPTIVE AND FLEXIBLE INTRUSION DETECTION SYSTEM FOR P2P BOTNET

机译:P2P僵尸网络自适应和灵活入侵检测系统的方法和装置

摘要

An intrusion detection system according to an embodiment proposes an adaptive and flexible intrusion detection method for detection of a P2P botnet. The intrusion detection system may comprise: a collection unit which collects pcap traffic in real time in an environment in which parallel operation is performed in a big data analysis cluster; a parsing unit which extracts features required for detection by parsing the collected pcap traffic; a P2P host detection unit which separates general network traffic and P2P traffic using the extracted features; and a botnet detection unit which detects a P2P botnet from the separate P2P traffic, and blocks the detected P2P botnet.
机译:根据实施例的入侵检测系统提出了一种用于检测P2P僵尸网络的自适应且灵活的入侵检测方法。入侵检测系统可以包括:收集单元,其在大数据分析集群中执行并行操作的环境中实时收集pcap流量;以及解析单元,通过解析收集到的pcap流量,提取检测所需的特征;一个P2P主机检测单元,使用提取的特征将一般网络流量和P2P流量分开;僵尸网络检测单元,用于从单独的P2P流量中检测P2P僵尸网络,并阻止检测到的P2P僵尸网络。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号