摘要
针对P2P僵尸网络的特点,将隐马尔可夫模型应用于P2P僵尸网络检测技术中.首先根据当前僵尸网络的发展状况及存在的问题分析了P2P僵尸网络的生命周期和行为特征;然后对僵尸主机的状态划分采用隐马尔可夫模型对P2P僵尸网络进行数学建模,并提出一种P2P僵尸网络的检测方法.通过实验,验证了检测方法的可靠性和合理性.
In accordance with the feature of P2P botnet, the Hidden Markov Model has application in P2P botnet detection. Firstly, according to the situation and problems of the botnet recently, the life cycle and behavior characteristics of the P2P botnet have been analyzed. After that a mathematical model has been built to describe the P2P botnet with the Hidden Markov Model in state division of the bot. Meanwhile, a method of P2P bother detection has been proposed. Finally, we analyzed and summarized the experimental results, and verified the reliability and rationality of the detection method.
出处
《微电子学与计算机》
CSCD
北大核心
2012年第10期14-17,共4页
Microelectronics & Computer
基金
中国科学院计算机网络信息中心青年基金项目(CNIC_QN_11003)