摘要
Botnet近来已经是网络安全中最为严重的威胁之一,过去出现的Botnet大多数是基于IRC机制,检测方法也大都是针对这种类型的。随着P2P技术的广泛应用,半分布式P2P Botnet已经成为一种新的网络攻击手段。由于半分布式P2P Botnet的servent bot的分布范围大、网络直径宽而冗余度小,造成的危害已越来越大,对半分布式的Botnet的检测研究具有现实意义。阐述了半分布式P2P Botnet的定义、功能结构与工作机制,重点分析了目前半分布式P2P Botnet几种流行的检测方法,并进行了对比;最后,对半分布式P2P Botnet检测方法的发展趋势进行了展望。
Recently, Botnet is already to be one of great threats in network security, which appeared in the past is mostly based on IRC mechanism, and the detecting methods are also mostly for this type. With the extensive use of P2P technology, half distributed peer-to,peer(P2P) Botnet has already become one kind of new network attacks. Due to spreading widely of servent hot and little redundanee, half distributed P2P Botnet threatens network security increasingly, so the research of the detecting methods about it has more practical significance. This paper addressed the definition, architecture, functions and mechanism of half distributed P2P Botnet, analyzed several popular detecting methods, and comparing with each other. Finally, discussed the detection method development trend of half distributed P2P Botnet.
出处
《计算机应用研究》
CSCD
北大核心
2009年第10期3925-3928,共4页
Application Research of Computers
基金
四川省科技厅基金资助项目(2008JY0105-2)
四川省教育厅基金资助项目(07ZA091)
实验室专项基金资助项目(2006ZD022)