首页> 外国专利> Camp;C DOMAIN NAME ANALYSIS-BASED BOTNET DETECTION METHOD, DEVICE, APPARATUS AND MEDIUM

Camp;C DOMAIN NAME ANALYSIS-BASED BOTNET DETECTION METHOD, DEVICE, APPARATUS AND MEDIUM

机译:基于C&C域名分析的僵尸网络检测方法,设备,装置和介质

摘要

Provided by the present invention are a C&C domain name analysis-based botnet detection method, device, apparatus and medium, the method comprising: an information acquisition step: obtaining a DNS log record; a domain name analysis step: according to a pre-built domain name analyzer, detecting C&C domain names in the DNS log record, and determining a category to which each C&C domain name belongs; a botnet determination step: determining whether a botnet is present according to the C&C domain names and the category to which the C&C domain names belong. The C&C domain name analysis-based botnet detection method, device, apparatus and medium provided by the present invention extract C&C domain names used for attack activity by means of analyzing a domain name system log record, thereby analyzing the type of parasitic Trojan horse, locking the zombie host controlled by a C&C server, and in addition, using the Poisson parameters occurring in the analysis of each type of C&C domain name to analyze a botnet activity trend in order to achieve timely development of effective suppression measures.
机译:本发明提供了一种基于C&C域名分析的僵尸网络检测方法,装置,装置和介质,包括:信息获取步骤:获取DNS日志记录;域名分析步骤:根据预先建立的域名分析器,在DNS日志记录中检测C&C域名,并确定每个C&C域名所属的类别。僵尸网络确定步骤:根据C&C域名和C&C域名所属的类别,确定是否存在僵尸网络。本发明提供的基于C&C域名分析的僵尸网络检测方法,装置,装置和介质,通过分析域名系统日志记录,提取用于攻击活动的C&C域名,从而分析了寄生木马的类型,锁定方式。由C&C服务器控制的僵尸主机,此外,还使用分析每种C&C域名时出现的Poisson参数来分析僵尸网络活动趋势,以便及时制定有效的抑制措施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号