节点文献

基于报文大小的P2P僵尸网络检测方法

P2P botnet detection method based on message size

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 谷海红何杰王浩

【Author】 GU Haihong;HE Jie;WANG Hao;Hebi Institute of Engineering and Technology,Henan Polytechnic University;Hebi Polytechnic;College of Computer,National University of Defense Technology;Department of Information and Communication,Officers College of PAP;

【通讯作者】 何杰;

【机构】 河南理工大学鹤壁工程技术学院鹤壁职业技术学院国防科技大学计算机学院武警警官学院信息通信系

【摘要】 作为当今互联网面临的最为严重的安全威胁之一,僵尸网络已从传统的集中式结构演化至更难检测的P2P分布式结构。对P2P僵尸网络实施有效检测是当前网络安全领域的研究热点之一。文中提出一个基于报文大小的P2P僵尸网络检测方法。该方法仅依靠网络报文大小这一统计值即可实现对处于潜伏阶段的P2P僵尸网络的检测,也可对未知类型的P2P僵尸网络实施检测。在大量真实数据集上的实验结果表明,该检测方法可达到较高的准确率,同时仅有较低的误报率。

【Abstract】 As one of the most serious security threats to Internet nowadays,the botnet has evolved their structure from traditional centralized structure to P2 P distributed structure,which makes them more difficult to be detected. The effective detection of P2 P botnet is one of the research hotspots in the field of network security. A P2 P botnet detection method based on message size is proposed,which can be used to realize the detection of P2 P botnet in the latent stage only by relying on the statistical value of network message size,and detect the unknown type of P2 P botnet. The experiment was carried out with a large number of real datasets. The results show that the detection method can achieve higher accuracy and lower false rate than those of others.

【基金】 国家自然科学基金资助项目(61170286)~~
  • 【文献出处】 现代电子技术 ,Modern Electronics Technique , 编辑部邮箱 ,2019年22期
  • 【分类号】TP393.08
  • 【下载频次】145
节点文献中: 

本文链接的文献网络图示:

本文的引文网络