论文部分内容阅读
僵尸网络作为一种新型的攻击手段对互联网安全产生重大威胁,随着僵尸网络技术的快速发展,基于多种协议的僵尸网络应运而生。针对僵尸网络的特点,将隐马尔可夫模型应用于僵尸网络检测技术中。首先根据当前僵尸网络的发展状况及存在的问题分析了僵尸网络的生命周期和行为特征;然后通过状态划分的方法对僵尸网络进行数学建模,并提出一种基于该模型的僵尸网络的检测方法;最后通过实验,并对实验结果进行分析与总结,验证了检测方法的可靠性和合理性。
As a new type of attack, botnets pose a significant threat to Internet security. With the rapid development of botnet technology, botnets based on multiple protocols emerge. According to the characteristics of the botnet, the hidden Markov model is applied to the botnet detection technology. Firstly, the life cycle and behavior characteristics of the botnet are analyzed according to the current situation and existing problems of the botnet. Then the botnet is mathematically modeled by the method of state division, and a botnet detection method based on the model is proposed Finally, through the experiment, the experimental results are analyzed and summarized, which verifies the reliability and rationality of the detection method.