计算机应用 ›› 2010, Vol. 30 ›› Issue (12): 3354-3356.

• 信息安全 • 上一篇    下一篇

多阶段过滤的P2P僵尸网络检测方法

刘丹1,李毅超2,胡跃2   

  1. 1. 电子科技大学
    2.
  • 收稿日期:2010-05-17 修回日期:2010-07-12 发布日期:2010-12-22 出版日期:2010-12-01
  • 通讯作者: 刘丹

P2P-Botnet detection based on multi-stage filtration

  • Received:2010-05-17 Revised:2010-07-12 Online:2010-12-22 Published:2010-12-01
  • Contact: Liu Dan

摘要: 提出基于流分析的P2P僵尸网络检测方法。首先基于节点连接分布性和突发性特征过滤掉非P2P节点,进而根据P2P节点对间连接度和流量的对称度,采用K均值聚类以发现各个P2P群,最后基于各P2P群内节点的流行为相似性检测是否为P2P僵尸网络。在局域网环境中的实验表明,该检测方法能够有效识别各种P2P僵尸网络,提高了检测效率和精度。

关键词: P2P网络, 僵尸网络, 聚类, 数据流, 恶意行为, 检测模型

Abstract: A new method for detecting P2P-Botnet, which was based on the analysis of network streams, was presented. Firstly, by using outburst and distributed characteristics of the P2P streams, the P2P nodes could be picked up from the common nodes. Then, based on the communication symmetry and cohesion characteristics of the pairs of nodes in a P2P network, the set of peers in one P2P network could be taken out by using the K-average cluster method. Finally, by contrasting with the common actions of the peers in every P2P network, a P2P-Botnet could be distinguished from the P2P networks. Plenty of experiments have been done in LAN environment and the results verified the efficiency and precision of the proposed method.

Key words: P2P network, Botnet, clustering, data stream, malicious behavior, detection model