计算机应用 ›› 2013, Vol. 33 ›› Issue (10): 2851-2853.

• 信息安全 • 上一篇    下一篇

基于重组的半分布式僵尸网络抗打击技术

朱俊虎,李鹤帅,王清贤,邱菡   

  1. 数学工程与先进计算国家重点实验室(信息工程大学),郑州 450002
  • 收稿日期:2013-03-27 修回日期:2013-05-04 出版日期:2013-10-01 发布日期:2013-11-01
  • 通讯作者: 朱俊虎
  • 作者简介:朱俊虎(1974-),男,江苏镇江人,副教授,主要研究方向:僵尸网络、虚拟化应用、网络防御技术测评;李鹤帅(1987-),男,山东日照人,博士研究生,主要研究方向:僵尸网络、网络防御技术测评;王清贤(1960-),男,河南卫辉人,教授,博士生导师,主要研究方向:信息安全、算法分析;邱菡(1981-),女,湖北随州人,讲师,博士,主要研究方向:互联网技术、电信技术。

Regroup-based semi-distributed botnet anti-strike technology

ZHU Junhu,LI Heshuai,WANG Qingxian,QIU Han   

  1. National Key Laboratory of Mathematical Engineering and Advanced Computing (Information Engineering University), Zhengzhou Henan 450002, China
  • Received:2013-03-27 Revised:2013-05-04 Online:2013-11-01 Published:2013-10-01
  • Contact: ZHU Junhu

摘要: 僵尸网络防御技术的不断涌现对僵尸网络生存能力提出了严峻的挑战,为了改善僵尸网络的生存能力,从攻击者角度提出一种适用于半分布式僵尸网络的基于重组的抗打击技术。通过对僵尸网络生存状态的感知和对存活节点的探查,实现了半分布式僵尸网络在遭受严重打击导致拓扑结构破碎情况下,寻回存活节点并将其重组为新的僵尸网络。通过实验验证了该技术的有效性,证明其能够有效增强半分布式僵尸网络的生存能力

关键词: 半分布式, 僵尸网络, 生存能力, 重组, 抗打击

Abstract: The newly developed botnet defense technologies pose a severe challenge to botnet survivability. In order to improve the survivability of the botnet, from an attackers perspective, this article proposed a new anti-strike mechanism based on regroup, which was suitable for semi-distributed botnet. In the case that semi-distributed botnet suffered a severe blow, which caused topology broken, this mechanism could perceive the state of botnet, detect survival nodes, recover survival node and reassemble them into a new botnet. The experiments verify the effectiveness of the mechanism to effectively enhance the survivability of the semi-distributed botnet.

Key words: semi-distributed, botnet, survivability, regroup, anti-strike

中图分类号: