Botnet detecting method based on group-signature filter
|更新时间:2024-10-14
|
Botnet detecting method based on group-signature filter
Vol. 31, Issue 2, Pages: 29-35(2010)
作者机构:
1. 天津理工大学计算机视觉与系统省部共建教育部重点实验室
2. 天津理工大学智能计算及软件新技术天津市重点实验室
3. 国家计算机病毒应急处理中心
作者简介:
基金信息:
DOI:
CLC:TP393.08
Published:2010
稿件说明:
移动端阅览
WANG Jin-song1, LIU Fan1, ZHANG Jian3. Botnet detecting method based on group-signature filter[J]. 2010, 31(2): 29-35.
DOI:
WANG Jin-song1, LIU Fan1, ZHANG Jian3. Botnet detecting method based on group-signature filter[J]. 2010, 31(2): 29-35.DOI:
Botnet detecting method based on group-signature filter
摘要
提出了一种基于组特征过滤器的检测方法
使用多个成员特征对内网主机数据分组进行过滤
以O(tmn)的空间开销为代价
应对短特征串和特征串的分组分散问题
并能与传统的特征匹配算法相兼容。模拟实验证明了该检测算法的正确性和有效性。
Abstract
A botnet detecting method was presented based on group-signature filter
suitable for the traditional signatures matching algorithm.Using multiple member signatures to filter the packets of hosts from Intranet
the proposed method is able to handle the shortened and scattered signatures at a space expense of O(tmn).The simulated experiment proves the correctness and validity of the detecting method.