论文部分内容阅读
传统僵尸程序依赖于集中控制,P2P僵尸的传播和控制方式都是分布式的,使其更具隐蔽性和健壮性.本文通过分析P2P僵尸的特征,对其控制行为进行了较为深入的研究.首先,阐述了控制流相似性的概念并对其做出合理量化;其次,利用皮尔逊序列假设检验法来识别P2P僵尸控制行为;最后,通过自动分类技术来进行二次判定,以完成自动检测.实验和数据分析表明该方法能够有效的识别校园网内P2P僵尸的控制行为,与相关的方法相比,误报显著降低.
Traditional zombie programs rely on centralized control, P2P zombies are distributed and controlled in a more invisibility and robustness.This paper analyzes the P2P bot’s characteristics and conducts a more in-depth study on its control behavior. First of all, the concept of control flow similarity is expounded and a reasonable quantification is made. Secondly, Pearson sequence hypothesis testing is used to identify the P2P zombie control behavior. Finally, the automatic decision is made by automatic classification to complete automatic detection Experiments and data analysis show that this method can effectively identify the control behavior of P2P zombies on the campus network, and the false positives are significantly reduced compared with the related methods.