通信学报2011,Vol.32Issue(4):66-76,11.
基于通信特征和D-S证据理论分析僵尸网络相似度
Botnets' similarity analysis based on communication features and D-S evidence theory
摘要
Abstract
A potential hidden relationship may exist among different zombie groups. A method to analyze the relationship among botnets was proposed based on the communication activities. The method extracted several communication features of botnet, including the number of flows per hour, the number of packets per flow, the number of flows per IP and the packet payloads. It defined similarity statistical functions of the communication features, and built the analysis model of botnets relationship based on the advanced dempster-shafer (D-S) evidence theory to synthetically evaluate the similarities between different zombie groups. The experiments were conducted using several botnet traces. The results show that the method is valid and efficient, even in the case of encrypted botnet communication messages. Moreover, the ideal processing results is achieved by applying our method to analyze the data captured from the security monitoring platform of computer network, as well as compare with similar work.关键词
僵尸网络/D-S证据理论/数据流/相似度Key words
botnet/ D-S evidence theory/ data flow/ similarity分类
信息技术与安全科学引用本文复制引用
臧天宁,云晓春,张永铮,门朝光,崔翔..基于通信特征和D-S证据理论分析僵尸网络相似度[J].通信学报,2011,32(4):66-76,11.基金项目
国家自然科学基金资助项目(60703021,61070185,60873138) (60703021,61070185,60873138)
国家高技术研究发展计划("863"计划)基金资助项目(2007AA010501,2009AA01Z431) ("863"计划)