西安交通大学电子与信息工程学院,西安,710049
网络首发:2012-04-10,
纸质出版:2012
移动端阅览
夏秦, 王志文, 刘璐. 基于域名共现行为的僵尸网络行为追踪[J]. 西安交通大学学报, 2012,46(4):7-12.
Tracking Botnet Activity Based on Co-Occurrence Relation of Domain Name System Queries[J]. 2012, 46(4): 7-12.
针对局部行为特征信息偏少而使得僵尸网络行为难以全面追踪的问题
提出了一种基于域名共现行为的僵尸网络行为追踪方法.该方法通过域名共现评分算法计算待测域名与已知僵尸域名的域名共现行为来追踪其他僵尸域名
进而发现更多的僵尸主机; 为提高域名评分准确性
还提出了过滤基于网络地址转换的主机域名访问、空间区分单个僵尸网络
以及基于观测时长共现行为统计3项改进措施.采集西安交通大学网络域名服务器的域名查询流量作为数据源进行了实验和测试
结果表明:基于改进的域名评分措施不仅将待测域名数量降为原来的1/4
且计算出的前10名域名共现评分更加合理
提高了追踪僵尸主机的准确性.
Botnet activities can't be tracked entirely with traditional methods because of the deficiency of information in local behavioral feature. A novel approach on tracking Botnet activity is presented based on co-occurrence relation of domain name system(DNS)queries. An algorithm is utilized to calculate the co-occurrence between undetermined DNS and known Botnet DNS so as to find some other Botnet DNS. Three improved measures are proposed in order to increase the accuracy of evaluating co-occurrence. The three measures are filtering DNS access by network address translation
differentiating individual spatial Botnet and observation time based statistic of co-occurrence. Experiments are carried out with test data of DNS queries collected in the campus network of Xi'an Jiaotong University. The results show that some advantages are acquired obviously with the improved measures
such as the number of undetermined DNS can fall to a quarter of traditional method
the co-occurrence acquired is more suitable for the top ten DNS and the accuracy is improved in finding zombies.
KONRAD R, GUIDO S, TOBIAS L, et al. Detecting the phoning home of malicious software [C]∥Proceeding of the 2010 Symposium on Applied Computing. Los Alamitor, CA, USA: IEEE Computer Society, 2010:298-304.
PETER W, LEYLA B, THORSTEN H, et al. Automatically generating models for Botnet detection[C]∥Proceeding of Symposium on Research in Computer Security. Los Alamitos, CA, USA: IEEE Computer Society, 2009:104-110.
MCCUSKER O, KIAYIAS A, WALLUCK D, et al. A combined fusion and mining strategy for detecting Botnets [J]. International Journal of Information Security, 2009, 8(11):71-82.
HE Yuanchen, ZHONG Zhenyu, TANG Yuchun. Mining DNS for malicious domain registrations [J]. Journal of the ACM, 2010, 12(32):335-348.
胡欣, 沈涛. 僵尸网络全局IP使用模式测量与分析 [J]. 计算机学报, 2011, 34(2): 207-214.
HU Xin, SHEN Tao. Measurement and analysis of global IP-usage patterns of Botnets [J]. Chinese Journal of Computers, 2011, 34(2): 207-214.
VILLAMAR R, BRUSTOLONI J C. Identifying Botnets using anomaly detection techniques applied to DNS traffic [C]∥Proceeding of the 5th IEEE Consumer Communications and Networking Conference. Los Alamitos, CA, USA: IEEE Computer Society, 2008:476-481.
SATO K, ISHIBASHI K. Extending black domain name list by using co-occurrence relation between DNS queries [C]∥ Proceeding of the 2010 USENIX Workshop on Large-Scale Exploits and Emergent Threats. Los Alamitor, CA, USA: IEEE Computer Society, 2010:2011-2020.
应用部分马尔科夫博弈的网络安全主动响应决策模型. 2011,45(4): 18-24.
使用交叉熵检测和分类网络异常流量. 2010,44(6):10-15.
网络结构鲁棒性指标及应用研究. 2010,44(4):93-97.
一种面向传感器网络的蚁群优化路径恢复算法. 2010,44(1):83-86.
最大化网络有效寿命的传感器网络覆盖保持协议. 2009,43(10):66-70.
一种相邻节点协作的无线传感器网络可靠传输方案. 2009,43(2):33-37.
网络安全协同防卫系统研究与实现. 2008,42(12):1495-1499.
利用最大似然准则的双向联想网络研究. 2008,42(12):963-966.
一种面向网络行为因果关联的攻击检测方法. 2008,42(8):931-935.
无线传感器网络低时延能量均衡安全路由. 2008,42(2):161-165.
0
浏览量
4
下载量
3
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621