Dissertation > Excellent graduate degree dissertation topics show

The botnet detection of abnormal behavior - based features

Author: YangQi
Tutor: HeJuHou
School: Shaanxi Normal University
Course: Applied Computer Technology
Keywords: Botnet IRC Bot Channel Response Cluster
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 85
Quote: 0
Read: Download Dissertation

Abstract


Botnet is a centralized control computer group secretly builded through Internet by attacker. It can on a large scale refuse the service attack, send junk e-mails, phishing and so on. Detecting the botnet quickly and effectively can prevent from some network events. However, the controlled computer coverage, type of complex and diverse, this is a botnet detection challenges. Fast and accurate detection of botnets as a major research direction in this field.This paper analyzes the IRC protocol based on the functions of botnet structure and working mechanism, and present several common botnet detection algorithm of the advantages and disadvantages, From the zombie channel under the control of the host’s response to the characteristics of unusual behavior, abnormal behavior is proposed based on characteristics of the zombie channel detection algorithm. Design and Implementation of IRC-based botnet detection of abnormal behavior characteristics of the prototype system, and This algorithm effects on the assessment of the effectiveness of this algorithm to verify. This major work includes:(1)Botnets work process analysis combined with the current advantages and disadvantages of traditional detection algorithm, verify the program based on the feasibility of detecting abnormal behavior, and give a feature-based botnet detection framework for abnormal behavior.(2)Successfully built a zombie network operating environment, and zombie zombies under control channel attacks who conducted a comprehensive simulation analysis, extract the abnormal behavior under the zombie host characteristics, by comparing the difference between the IRC Bot channels and IRC chat channels.(3)Giving a botnet detection algorithm based on abnormal behavior, The algorithm main problem is to identify the IRC chat channel in the host response towards an order in time and space correlation, according to the host is detected for a certain period of time in order to respond to the similarity, to determine whether the current channel used by an attacker to build a botnet.(4)Design and implementation for this IRC-based botnet detection of abnormal behavior characteristics of the prototype system, respectively, for the normal IRC channels and implanted into the IRC Bot channel analysis of two aspects of the experiment to verify the effectiveness of this algorithm and framework.

Related Dissertations

  1. Research of IRC Botnet Detection Based on Behavior,TP393.08
  2. Research and Implementation of Bot Detection Based on API Hook Technology,TP393.08
  3. Loop stepper delay range-gated imaging study three-dimensional display,TP391.41
  4. Packet-based feature zombie Trojan detection technology,TP393.08
  5. Research and Implementation of Forensics System on DDoS Attack Based on Botnet,TP393.08
  6. Mobile Ad Hoc Network Intrusion Detection and Response System Based Cluster,TN929.5
  7. Research on Botnet Detection Technologies Based on DNS Traffic,TP393.08
  8. P2P Botnet Detection in Small and Medium LAN,TP393.1
  9. The low interaction malicious software capture technology,TP393.08
  10. Metformin on high free fatty acids and high glucose-induced islet β cells and HIT-T15 cells Role of insulin resistance improvement,R587.1
  11. Analysis and Detection of Botnet Anomaly Traffic,TP393.08
  12. LTE downlink MIMO technology receives Algorithm,TN929.5
  13. Study and Realize on IRC Based Network Flow Detection Model,TP393.08
  14. Research and Design of the Honeynet to Defend the DDoS Attack from Botnet,TP393.08
  15. Based on flow characteristics of IRC Botnet Detection Technology Research,TP393.08
  16. On the Register Features of Netlish of IRC,H315
  17. The Research on Web Application and Data Security,TP393.08
  18. Research on Countermeasure Techniques for the Botnet,TP393.08
  19. Research on Botnets’ Analysis Technologies in Large Scale Network,TP393.08
  20. Behavior Based Spam Detection and Analysis in Online Social Network,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile