ZANG Tian-ning1, YUN Xiao-chun1, ZHANG Yong-zheng2, et al. Botnets’ similarity analysis based on communication features and D-S evidence theory[J]. 2011, 32(4): 66-76.
ZANG Tian-ning1, YUN Xiao-chun1, ZHANG Yong-zheng2, et al. Botnets’ similarity analysis based on communication features and D-S evidence theory[J]. 2011, 32(4): 66-76.DOI:
基于通信特征和D-S证据理论分析僵尸网络相似度
摘要
不同僵尸网络之间可能具有潜在的隐藏关系
根据僵尸网络通信行为提出分析僵尸网络之间关系的方法
提取僵尸网络内部通信的数据流数量、流中数据分组数量、主机通信量和数据分组负载等特征
并定义特征相似度统计函数
通过改进D-S证据理论
建立分析僵尸网络之间关系的模型
综合评判两批僵尸主机群相似度。经过典型样本评测
验证了该方法的良好分析效果
且可弱化加密通信的影响。分析了基础网络安全监测平台捕获的僵尸网络数据
并与相关工作比较
突出了该方法的技术先进性。
Abstract
A potential hidden relationship may exist among different zombie groups.A method to analyze the relationship among botnets was proposed based on the communication activities.The method extracted several communication fea-tures of botnet
including the number of flows per hour
the number of packets per flow
the number of flows per IP and the packet payloads.It defined similarity statistical functions of the communication features
and built the analysis model of botnets relationship based on the advanced dempster-shafer(D-S) evidence theory to synthetically evaluate the simi-larities between different zombie groups.The experiments were conducted using several botnet traces.The results show that the method is valid and efficient
even in the case of encrypted botnet communication messages.Moreover
the ideal processing results is achieved by applying our method to analyze the data captured from the security monitoring platform of computer network