首页 | 本学科首页   官方微博 | 高级检索  
     

基于神经网络的僵尸网络检测
引用本文:蒋鸿玲,邵秀丽.基于神经网络的僵尸网络检测[J].智能系统学报,2013,8(2):113-118.
作者姓名:蒋鸿玲  邵秀丽
作者单位:南开大学 信息技术科学学院,天津 300071
摘    要:目前主流的僵尸网络检测方法主要利用网络流量分析技术,这往往需要数据包的内部信息,或者依赖于外部系统提供的信息或僵尸主机的恶意行为,并且大多数方法不能自动存储僵尸网络的流量特征,不具有联想记忆功能.为此提出了一种基于BP神经网络的僵尸网络检测方法,通过大量的僵尸网络和正常流量样本训练BP神经网络分类器,使其学会辨认僵尸网络的流量,自动记忆僵尸流量特征,从而有效检测出被感染的主机.该神经网络分类器以主机对为分析对象,提取2个主机间通信的流量特征,将主机对的特征向量作为输入,有效地区分出正常主机和僵尸主机.实验表明,该方法的检测率达到99%,误报率在1%以下,具有良好的性能.

关 键 词:僵尸网络  BP神经网络  特征向量  网络流量  检测算法

Botnet detection algorithm based on neural network
JIANG Hongling,SHAO Xiuli.Botnet detection algorithm based on neural network[J].CAAL Transactions on Intelligent Systems,2013,8(2):113-118.
Authors:JIANG Hongling  SHAO Xiuli
Affiliation:College of Information Technical Science, Nankai University, Tianjin 300071, China
Abstract:The most current botnet detection algorithm are typically based on network traffic analyzing technologies that usually need packet payload. The botnet detection algorithm also relies on information obtained by external systems or malicious behaviors of bots that do not automatically store the features of botnet traffic and do not have the ability of associative memory. As a result, this paper proposes a botnet detection algorithm based on BP neural network which trains the BP neural network classifier through a lot of botnet and normal traffic samples and allows it to learn how to identify botnet traffic and automatically remember the features of botnet traffic and therefore, detect the infected hosts effectively. The neural network classifier takes the host-pairs as analysis objects, extracts the traffic features of communications between two hosts and takes the feature vectors of host-pairs as input, thus, effectively distinguishing the normal hosts and bots. The experimental results show that the detection rate of our algorithm can achieve to 99% and the false positive rate is below 1% and the algorithm has a good performance.
Keywords:botnet  BP neural network  feature vector  network traffic  detection algorithm
点击此处可从《智能系统学报》浏览原始摘要信息
点击此处可从《智能系统学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号