计算机应用 ›› 2010, Vol. 30 ›› Issue (3): 692-694.
• 信息安全 • 上一篇 下一篇
范轶彦1,邬国锐2
收稿日期:
修回日期:
发布日期:
出版日期:
通讯作者:
Received:
Revised:
Online:
Published:
Contact:
摘要: 现有的僵尸网络技术和检测方法通常局限于某种特定的僵尸网络。为提高僵尸网络的隐秘性,提出了一种动态僵尸网络模型,利用有向图进行描述,可以表示不同类型的僵尸网络。对模型的暴露性、可恢复性和可持续性等动态属性进行量化分析,给出了一种僵尸主机主动丢弃原则。实验结果表明,提出的方法可以有效降低僵尸网络检测率,提高僵尸网络的可持续性和可恢复性。
关键词: 僵尸网络, 僵尸主机, 有向图, 丢弃原则, 检测率
Abstract: The existing Botnet techniques and detection methods are usually confined to specific Botnet. To improve the confidentiality of Botnet, the authors proposed a dynamic Botnet model described with directed graph, which can accommodate various Botnets. Several dynamic attributes of the proposed model were analyzed, such as exposedness, resilience, sustainability in detail, and then a bot abandon policy was presented. The experimental results indicate that the proposed method can decrease the Botnet's detection ratio and improve sustainability and resilience effectively.
Key words: Botnet, Bot, directed graph, abandon policy, detection rate
范轶彦 邬国锐. 动态僵尸网络模型研究[J]. 计算机应用, 2010, 30(3): 692-694.
0 / 推荐
导出引用管理器 EndNote|Ris|BibTeX
链接本文: https://www.joca.cn/CN/
https://www.joca.cn/CN/Y2010/V30/I3/692