作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (14): 111-113. doi: 10.3969/j.issn.1000-3428.2010.14.040

• 安全技术 • 上一篇    下一篇

半分布式P2P僵尸网络的伪蜜罐检测方法

谢 静1,谭 良1,2   

  1. (1. 四川师范大学计算机学院,成都 610068;2. 中国科学院计算技术研究所,北京 100080)
  • 出版日期:2010-07-20 发布日期:2010-07-20
  • 作者简介:谢 静(1984-),女,硕士,主研方向:信息安全;谭 良,博士后
  • 基金资助:

    四川省科技厅应用基础研究基金资助项目(2008JY0105-2);四川省教育厅自然科学基金资助项目(07ZA091);四川省教育厅计算机软件重点实验室专项基金资助项目(2006ZD022)

Fake-honeypot Detection Method for Semi-distributed Peer-to-Peer Botnet

XIE Jing1, TAN Liang1,2   

  1. (1. College of Computer, Sichuan Normal University, Chengdu 610068; 2. Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100080)
  • Online:2010-07-20 Published:2010-07-20

摘要:

在攻击与防御的博弈中,半分布式P2P僵尸网络随着P2P的广泛应用已成为僵尸网络最主要的形式。为此,描述攻击者组建的半分布式P2P僵尸网络的构建原理和增长模型,提出蜜罐与流量分析技术相结合的“伪蜜罐”检测模型,即在主机出现网络异常时,关闭已知程序和服务,使主机向蜜罐身份靠近,并用流量分析技术检测的一种模型。实验结果表明,该检测方法能够有效地提高半分布式P2P僵尸网络的检出率。

关键词: 半分布式P2P僵尸网络, 伪蜜罐, 流量分析, 模型分析

Abstract:

In the game of attack and defense, semi-distributed P2P botnet becomes the most dominant form of botnet as the applications of P2P are widely used. This paper describes the basic principle of how the attackers create their semi-distributed botnet and the model of its increasing, proposes the “faked honeypot” detection model, which combines honeypot and the flow analysis. When anomalies appear in host network, the programs and services are closed, the host is made to lay aboard to the honeypot, and detected by flow analysis. Experimental result shows that the method can effectively improve the detection rate of semi-distributed P2P botnet.

Key words: semi-distributed P2P botnet, fake-honeypot, analysis of flow, model analysis

中图分类号: