一种基于模糊逻辑的P2P僵尸网络防御模型

来源 :清华大学学报(自然科学版) | 被引量 : 0次 | 上传用户:tower2008
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
僵尸网络已经成为当前网络中的主要安全威胁之一,特别是P2P僵尸网络的发展,使得僵尸网络的生存能力大大提高。针对P2P僵尸网络提出了一种僵尸网络防御模型FLBDM,该模型分为检测、分析、反制3个部分。首先,基于模糊逻辑理论,提出了僵尸网络检测模型FLDBM;其次,引入蜜罐网络对僵尸程序进行分析;最后,引入认证僵尸网络对原僵尸网络进行反制。仿真实验表明:与CUSUM相比,FLBDM防御模型有着良好的检测成功率,以及较低的误报率,并能有效地对僵尸网络进行破坏。 Botnets have become one of the major security threats in the current network. In particular, the development of P2P botnets has greatly enhanced the viability of botnets. A botnet defense model FLBDM is proposed for P2P botnet. The model is divided into three parts: detection, analysis and countermeasure. First of all, based on the theory of fuzzy logic, the botnet detection model FLDBM is proposed. Secondly, the honeypot network is introduced to analyze the bot programs. Finally, the authentication botnet is introduced to counter the original botnet. Simulation results show that compared with CUSUM, FLBDM defense model has a good detection success rate, as well as a lower false alarm rate, and can effectively destroy the botnet.
其他文献
基于GIS技术,结合旅游域模型,获得长三角地区各旅游中心城市旅游圈旅游吸引物数据,运用分形方法对其空间结构进行聚集维数的测算与分析。认为各旅游圈旅游吸引物体系具有聚集