作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (08): 92-94. doi: 10.3969/j.issn.1000-3428.2012.08.030

• 安全技术 • 上一篇    下一篇

基于Kademlia的新型半分布式僵尸网络

李鹤帅,朱俊虎,周天阳,王清贤   

  1. (国家数字交换系统工程技术研究中心,郑州 450002)
  • 收稿日期:2011-06-21 出版日期:2012-04-20 发布日期:2012-04-20
  • 作者简介:李鹤帅(1987-),男,硕士研究生,主研方向:网络信息安全;朱俊虎,副教授、硕士;周天阳,硕士;王清贤,教授

New Semi-distributed Botnet Based on Kademlia

LI He-shuai, ZHU Jun-hu, ZHOU Tian-yang, WANG Qing-xian   

  1. (National Digital Switching System Engineering and Technological Research Center, Zhengzhou 450002, China)
  • Received:2011-06-21 Online:2012-04-20 Published:2012-04-20

摘要: 使用Kademlia协议的僵尸网络可利用海量合法流量隐藏攻击行为,但单纯使用Kademlia容易被防火墙拦截。针对该问题,设计一种基于Kademlia的新型半分布式僵尸网络。通过将Hybrid Botnet的主干部分由非结构化网络改为Kademlia网络,使之能规避防火墙,同时网络流量较小,通过仿真实验证明新型僵尸网络较传统网络具有更好的流量特性和鲁棒性。并给出3种抵御新型网络的防御措施。

关键词: Kademlia网络, 命令控制机制, P2P网络, 半分布式, 僵尸网络, 防火墙

Abstract: Botnet based on Kademlia can easily be hidden in the legitimate traffic, but Botnet which uses Kademlia as its protocol may be detected because of firewall’s blocking. This paper designs a new semi-distributed Botnet based on Kademlia. By changing hybrid Botnet’s backbone from unstructured network to Kademlia network, it can circumvent firewall and has small flow. Simulation comparison experiments show that the new Botnet has better flow characteristics and robustness than traditional Botnets. And three kinds of defensive mechanisms against the designed Botnet are proposed.

Key words: Kademlia network, Command and Control(C&C) mechanism, P2P network, semi-distributed, Botnet, firewall

中图分类号: