首页 | 本学科首页   官方微博 | 高级检索  
     

基于流量摘要的僵尸网络检测
引用本文:肖喜生,龙春,杜冠瑶,魏金侠,赵静,万巍.基于流量摘要的僵尸网络检测[J].计算机系统应用,2021,30(8):186-193.
作者姓名:肖喜生  龙春  杜冠瑶  魏金侠  赵静  万巍
作者单位:中国科学院 计算机网络信息中心, 北京 100190;中国科学院大学 计算机科学与技术学院, 北京 101408;中国科学院 计算机网络信息中心, 北京 100190
基金项目:国家重点研发计划网络空间安全重点专项(2017YFB0801902);中国科学院“十四五”网信专项先期建设项目(WX145XQ11)
摘    要:随着僵尸网络的日益进化,检测和防范僵尸网络攻击成为网络安全研究的重要任务.现有的研究很少考虑到僵尸网络中的时序模式,并且在实时僵尸网络检测中效果不佳,也无法检测未知的僵尸网络.针对这些问题,本文提出了基于流量摘要的僵尸网络检测方法,首先将原始流数据按照源主机地址聚合,划分适当的时间窗口生成流量摘要记录,然后构建决策树、随机森林和XGBoost机器学习分类模型.在CTU-13数据集上的实验结果表明,本文提出的方法能够有效检测僵尸流量,并且能够检测未知僵尸网络,此外,借助Spark技术也能满足现实应用中快速检测的需要.

关 键 词:僵尸网络  机器学习  Spark  流量摘要
收稿时间:2020/11/23 0:00:00
修稿时间:2020/12/22 0:00:00

Botnet Detection Based on Flow Summary
XIAO Xi-Sheng,LONG Chun,DU Guan-Yao,WEI Jin-Xi,ZHAO Jing,WAN Wei.Botnet Detection Based on Flow Summary[J].Computer Systems& Applications,2021,30(8):186-193.
Authors:XIAO Xi-Sheng  LONG Chun  DU Guan-Yao  WEI Jin-Xi  ZHAO Jing  WAN Wei
Affiliation:Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China;School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 101408, China
Abstract:With the development of botnets, detecting and preventing botnet attacks has become an important task of network security research. Existing studies, which rarely consider the timing patterns in botnets, are ineffective in real-time botnet detection and cannot detect unknown botnets. To tackle these problems, this study proposes a flow summary based botnet detection method. First, the network flow data is aggregated according to the source host IPs, and the flow summary records are generated in a given time window. Then, decision tree, random forest, and XGBoost machine-learning classification models are built to validate the performance of our method. The experimental results on the CTU-13 dataset show that the method we propose can effectively detect botnet traffic and detect unknown botnets. With the help of Spark technology, our method can also meet the needs of rapid detection in real applications.
Keywords:botnet  machine learning  Spark  flow summary
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机系统应用》浏览原始摘要信息
点击此处可从《计算机系统应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号