WANG Jin-song1, LIU Fan1, ZHANG Jian3. Botnet detecting method based on group-signature filter[J]. 2010, 31(2): 29-35.DOI:
基于组特征过滤器的僵尸主机检测方法的研究
摘要
提出了一种基于组特征过滤器的检测方法
使用多个成员特征对内网主机数据分组进行过滤
以O(tmn)的空间开销为代价
应对短特征串和特征串的分组分散问题
并能与传统的特征匹配算法相兼容。模拟实验证明了该检测算法的正确性和有效性。
Abstract
A botnet detecting method was presented based on group-signature filter
suitable for the traditional signatures matching algorithm.Using multiple member signatures to filter the packets of hosts from Intranet
the proposed method is able to handle the shortened and scattered signatures at a space expense of O(tmn).The simulated experiment proves the correctness and validity of the detecting method.