›› 2010, Vol. 23 ›› Issue (11): 109-112.

• 论文 • 上一篇    下一篇

基于异常行为特征的僵尸网络检测方法研究

杨奇,何聚厚   

  1. (陕西师范大学 计算机科学学院,陕西 西安 710062)
  • 出版日期:2010-11-15 发布日期:2010-12-23
  • 作者简介:杨奇(1984-),男,硕士研究生。研究方向:计算机网络安全。

Abnormal Behavior-Based Botnet Detection Algorithm

 YANG Qi, HE Ju-Hou   

  1. (School of Computer Science,Shaanxi Normal University,Xi'an 710062,China)
  • Online:2010-11-15 Published:2010-12-23

摘要:

基于僵尸网络通信及网络流量的异常行为,可以有效检测出僵尸频道。介绍了通过对主机响应信息的异常分析,进而判断出当前IRC频道是否为一个僵尸频道的检测算法。由此引入了基于异常行为的僵尸频道检测模型,该模型分类提取IRC频道的主机响应信息,结合检测算法分析得出结论。实验结果验证了该模型的有效性。

关键词: 僵尸网络, 僵尸频道, 响应集群

Abstract:

The zombie network communications and network traffic based abnormal behavior can detect the botnet channel effectively.This paper describes an algorithm which can determine whether the current IRC channel is a botnet channel or not through the analysis of the information on the response.The Anomaly-based detection model about the botnet channel is introduced,which extracts the information on the response and draws a conclusion by the testing algorithm.The experimental results verify the validity of the model.

Key words: botnet;botnet channel;response clusters

中图分类号: 

  • TP393