|
With the rapid development and wide application of computer network technology, especially the rapid spread of the Internet to promote innovation and upgrade of computer and Internet technology. The growing network facilities and resources for the importance of the state, enterprises and individuals, in changing people's traditional way of life, work, and learn ways at the same time it also brings new problems and challenges. Human society, the degree of information is increasing, and increasing dependence on the network, and the normal of the information society, how can we ensure safe and smooth operation of computer network security is one of the most important aspects, must continue to be able to enrich strengthen and improve. Currently, the breadth and depth of the field of network interconnection continues to expand, the deepening open nature, caused by the increasing number of network systems face the threat of attacks and intrusions. Botnets (Botnet) with automatic application of intelligent program development. Worm technology continues to mature, the spread of the zombie virus worms active communication technologies, which can quickly build a large-scale botnets (Botnet). Botnet is a new attack evolved from a traditional malicious code form, provide an attacker with the occult, flexible and efficient one-to-many command and control mechanisms, can control a large number of zombie hosts information theft, distributed denial of service attacks and spammers attack purposes. The botnet is entering a period of rapid development, has caused a serious threat to Internet security. Botnet is just emerging, the methods used are mostly traditional reverse engineering methods. First, reverse engineering analysis of virus samples, found by analyzing their signatures. And according to the signature capture and processing of the zombie virus. But a lot of ills of this detection method used in traditional virus that zombie viruses are generally long incubation period, does not exhibit the traditional characteristics of the virus during the incubation period. Thus, traditional methods of analysis will lose its effectiveness. In addition, due to the development of the virus technology in recent years, a variety of viruses packers technology after another, to the use of the traditional virus reverse engineering analysis methods brought great difficulties. In the above context, as well as expand the collection of data mining and network intrusion detection to detect botnet explore 242 project - P2P botnet detection and anti-system \First, a brief description, and classified intrusion detection and data mining technology background. Botnet detection intrusion detection based on data mining technology and then discusses and proposes a new mechanism based on the detection of the communication session between the botnet zombie machines. Finally, the full text of the work summarized in this thesis, the problems and the direction of technology development.
|