Dissertation > Excellent graduate degree dissertation topics show
The Research on Approaches for Botnet Detection
Author: WangBinBin
Tutor: LiZhiTang
School: Huazhong University of Science and Technology
Course: Information Security
Keywords: Botnets Address anomalies corresponding relationship Interaction flow cluster distribution is similar Connection patterns of behavior Internet chat protocol Peer-to-peer network Detection methods
CLC: TP393.08
Type: PhD thesis
Year: 2010
Downloads: 451
Quote: 4
Read: Download Dissertation
Abstract
|
A botnet is a remote control of the attacker, and no user perception of a group of computer attack platform, has developed into one of the most serious security threats of today's Internet. The basic characteristics of the botnet is different from traditional Trojans, worms and other malicious attacks, the attacker uses a one-to-many command and control mechanisms (Command and Control, CC) to achieve full control of multiple hosts, commanding zombie collaborate initiated malicious activities, and use them to easily launch all kinds of large-scale cyber attacks such as distributed denial of service attack, sending mass spam. How to accurately identify the primary task of the zombie host defense botnets, network operations management, and so has a very important significance to combat cybercrime. Initially, botnets rely mainly on the IRC (Internet Relay Chat) and HTTP (Hyper Text Transport Protocol) protocol to achieve centralized CC control; later shortcomings, in order to overcome the centralized structure of the single point of failure, and start using P2P (Peer-to- The Peer) agreement to build a distributed architecture CC to strengthen its robustness and invisibility. Highly controlled environment of the botnet, an attacker can be related command frequently update the bot to change its signature, and therefore likely to fail detection method based on pattern matching. Identify bots: by parsing the associated communication protocols (such as IRC and HTTP), mining abnormal traffic behavior to identify bots; second is based on the with bots CC is similar communication behavior and aggression , clustering and association methods to identify types include IRC, HTTP and P2P bots. However, the former can not deal with encrypted communications; latter is dependent on the conditions of the supervision of the network there are several similar bots, difficult to identify a single zombie network host. In addition, the active measurement techniques is to identify the P2P bots effective method, but already such technologies the introduction of a large number of additional traffic to the network, will give greater impact normal node communication. Proposed the exception address corresponding relationship Storm bots active identification method AASD. Storm bots identifiable parasitic on the Overnet network is dangerous. The Overnet a DHT network, in theory, there is a one-to-one relationship between its node identifier and mailing address (IP, Port), but they actually found abnormal one-to-many and many-to-one correspondence between the said the one-to-many and said many-to-one mailing address reuse identifier reuse. Induction nodes index address entry identifier reuse and communication address reuse the basis of the phenomenon and found that the Storm zombie index address entry two characteristics: (1) the zombie node identifier and communication addresses having a reusable phenomenon; ( 2) each reuse identifier corresponding to multiple IP addresses are not focused on a specific subnet. Overnet network high-speed reptiles, deployed on PlanetLab the global experimental platform, collected a large number of the index used in the experiment address entry; using set theory method to identify the address of the node index entry identifier reuse and mailing address reuse phenomenon; Then, the maximum information entropy theory to quantify the degree of dispersion of the corresponding IP address reuse identifier, and the degree of dispersion as discriminant important basis for zombies. If the dispersity exceeds the set threshold value, corresponding to reuse identifier is Storm zombie identifier, which corresponds to the reuse of communication address is Storm zombies using the communication address. Experimental results show that: compared with existing proactive detection methods, AASD method can not only identify a recognition rate of 95% of the active Storm zombie nodes, but also to identify inactive Storm zombie nodes; In addition, the network bandwidth is reduced about 60% effective in reducing a normal Overnet nodes user. The proposed rate distribution based interactive flow clusters similar the P2P bots recognition method SIDPI. It can identify encrypted Storm bots. Specific IP port (IP, Port) called on a certain time window within stream flow clusters. Non zombie applications, the listening port in the window on the distribution of the average packet length of each stream cluster vary greatly, and zombies is similar. When the distance between the window distribution relative entropy theoretical quantization two adjacent distance computing the average packet streams clusters in the plurality of continuous long time window length distribution, distribution similar rate exceeds a set threshold value (IP, Port) of the host i.e. identified as bots. Also proposed a small stream cluster filtering algorithm, it extracts the listening port network suspected bots, cut to deal with network traffic, improve the efficiency of the the flow cluster distribution similarity judgment. SIDPI method advantages: (1) no load information package, bots can identify encrypted communication; (2) does not depend on multiple zombies similar group communication and similar attacks, a single zombie can identify the network, especially spread early in zombie. Experimental results show that the small flow filter algorithm can filter out more than 98% of the network (IP, Port) to improve the efficiency of subsequent similar rate determination; using encrypted communication and unencrypted communications Storm zombies average detection rate of about 95 %. The is proposed the zombie host identification method based on network connection behavior patterns BMBD. It identifies the currently active IRC and HTTP bots. The analysis found that the different connections with similar zombie node, these connections intervals having a periodic. For this reason, the first to use unsupervised clustering method of polymerization similar connection using a loop function mining potential cycle a BCM (Bot Connection-Behavior Model, BCM) mode. Then flow through the BCM pattern matching to identify bots crawl the network boundary. The experiments show that BMBD neither dependent on the the zombie host communication content does not depend on the zombie group behavior, able to detect a single zombie nodes within the network, the detection rate of more than 96%. Known BCM mode the zombies, BMBD method can detect the zombie variant detection rate of about 86.67%.
|
Related Dissertations
- Research on Botnet Traffic Detection Based on Spatial-temporal Correlation Analysis,TP393.08
- Design and Simulation of Peer-to-Peer Live Streaming System,TN919.8
- The Research and Implementation on Storage Management for P2P VOD System,TN948.64
- Behavior -based botnet detection method,TP393.08
- One kind of peer to peer network file sharing algorithm simulation and performance analysis and comparison,TP393.09
- TRF detection method combines traditional method to evaluate the quality of raw milk,TS252.7
- P2P Streaming Based on Scalable Video Coding,TP393.09
- Study on the Rapid Detection Method of Compaction Quality with Earth-rock Subgrade Based on PFWD,U416.1
- Studies on Establishment of HPLC Determination Methods of Aminoglycosides Residue in Seafood,TS254.7
- Cloud security technology in the data center botnet protection application,TP393.08
- Researcn of Chord-Based P2P Network Topology and Search Algorithm,TP393.02
- Research on Technologies of Search Engine Based on Peer-to-Peer Networks,TP391.3
- Research and Implementation of Federated Database Based on XML Metadata,TP311.13
- Collaborative Intrusion Detection Research in Peer-to-Peer Network,TP393.08
- Study and Implementation of the P2P-based Autonomic Learning and Collaborative Learning System,TP393.02
- Detection of Soybean Protein Isolate and Porcine Skeletal Muscle in Emulsion Sausage of Pork,TS251.65
- Research on Test Method and Evaluation Indexes about Interlayer Bonding of Asphalt Pavement,U416.217
- Study on Residue Dynamics of Lambda-cyhalothrin in Cabbage and Its Adsorption and Photochemical Degradation,S481.8
- The Quality of the Compound Simvastatin Niacin Slow-Released Tablet,R927
- The Research of Botnet Detection Algorithm,TP393.08
- Study on Digital Rights Management of Streaming Media Based on P2P Network,TP393.02
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|