计算机应用 ›› 2010, Vol. 30 ›› Issue (3): 692-694.

• 信息安全 • 上一篇    下一篇

动态僵尸网络模型研究

范轶彦1,邬国锐2   

  1. 1. 湖南文理学院 计算机学院
    2. 北京大学
  • 收稿日期:2009-09-07 修回日期:2009-10-28 发布日期:2010-03-14 出版日期:2010-03-01
  • 通讯作者: 范轶彦

Research of dynamic Botnet model

  • Received:2009-09-07 Revised:2009-10-28 Online:2010-03-14 Published:2010-03-01
  • Contact: Yiyan Fan

摘要: 现有的僵尸网络技术和检测方法通常局限于某种特定的僵尸网络。为提高僵尸网络的隐秘性,提出了一种动态僵尸网络模型,利用有向图进行描述,可以表示不同类型的僵尸网络。对模型的暴露性、可恢复性和可持续性等动态属性进行量化分析,给出了一种僵尸主机主动丢弃原则。实验结果表明,提出的方法可以有效降低僵尸网络检测率,提高僵尸网络的可持续性和可恢复性。

关键词: 僵尸网络, 僵尸主机, 有向图, 丢弃原则, 检测率

Abstract: The existing Botnet techniques and detection methods are usually confined to specific Botnet. To improve the confidentiality of Botnet, the authors proposed a dynamic Botnet model described with directed graph, which can accommodate various Botnets. Several dynamic attributes of the proposed model were analyzed, such as exposedness, resilience, sustainability in detail, and then a bot abandon policy was presented. The experimental results indicate that the proposed method can decrease the Botnet's detection ratio and improve sustainability and resilience effectively.

Key words: Botnet, Bot, directed graph, abandon policy, detection rate