计算机应用
計算機應用
계산궤응용
COMPUTER APPLICATION
2010年
3期
692-694
,共3页
僵尸网络%僵尸主机%有向图%丢弃原则%检测率
僵尸網絡%僵尸主機%有嚮圖%丟棄原則%檢測率
강시망락%강시주궤%유향도%주기원칙%검측솔
Botnet%Bot%directed graph%abandon policy%detection ratio
现有的僵尸网络技术和检测方法通常局限于某种特定的僵尸网络.为提高僵尸网络的隐秘性,提出了一种动态僵尸网络模型,利用有向图进行描述,可以表示不同类型的僵尸网络.对模型的暴露性、可恢复性和可持续性等动态属性进行量化分析,给出了一种僵尸主机主动丢弃原则.实验结果表明,提出的方法可以有效降低僵尸网络检测率,提高僵尸网络的可持续性和可恢复性.
現有的僵尸網絡技術和檢測方法通常跼限于某種特定的僵尸網絡.為提高僵尸網絡的隱祕性,提齣瞭一種動態僵尸網絡模型,利用有嚮圖進行描述,可以錶示不同類型的僵尸網絡.對模型的暴露性、可恢複性和可持續性等動態屬性進行量化分析,給齣瞭一種僵尸主機主動丟棄原則.實驗結果錶明,提齣的方法可以有效降低僵尸網絡檢測率,提高僵尸網絡的可持續性和可恢複性.
현유적강시망락기술화검측방법통상국한우모충특정적강시망락.위제고강시망락적은비성,제출료일충동태강시망락모형,이용유향도진행묘술,가이표시불동류형적강시망락.대모형적폭로성、가회복성화가지속성등동태속성진행양화분석,급출료일충강시주궤주동주기원칙.실험결과표명,제출적방법가이유효강저강시망락검측솔,제고강시망락적가지속성화가회복성.
The existing Botnet techniques and detection methods are usually confined to specific Botnet. To improve the confidentiality of Botnet, the authors proposed a dynamic Botnet model described with directed graph, which can accommodate various Botnets. Several dynamic attributes of the proposed model were analyzed, such as exposedness, resilience, sustainability in detail, and then a bot abandon policy was presented. The experimental results indicate that the proposed method can decrease the Botnet's detection ratio and improve sustainability and resilience effectively.