题名 | A novel botnet detection method based on preprocessing data packet by graph structure clustering |
作者 | |
发表日期 | 2017-02-23 |
会议名称 | 8th International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC) |
会议录名称 | Proceedings - 2016 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery, CyberC 2016
![]() |
ISBN | 978-1-5090-5154-0 |
页码 | 42-45 |
会议日期 | OCT 13-15, 2016 |
会议地点 | Chengdu, CHINA |
摘要 | Botnets are one of the most serious threats in the Internet, and thus the effective detection of the botnet becomes more and more important. In this paper, inspired by IP tracing technology, we propose a novel botnet detection method that can analyze the data packets, based on graph structure clustering. This method analyzes the comprehensive information of packages content and timestamp flow. Such a capability is achieved by improving the HEMST (Hierarchical Euclidean Minimum Spanning Tree) clustering algorithm. It performs a similarity matching process to find the sender of each cluster that is the controlled host in botnet. Experimental results show that the clustering correct rate can reach to 97% which demonstrates the effectiveness of our method, having a better detection rate. |
关键词 | Botnet detection Graph structure clustering IP traceback Match |
DOI | 10.1109/CyberC.2016.16 |
URL | 查看来源 |
收录类别 | CPCI-S |
语种 | 英语English |
WOS研究方向 | Computer Science |
WOS类目 | Computer Science, Interdisciplinary Applications ; Computer Science, Theory & Methods |
WOS记录号 | WOS:000401467600006 |
Scopus入藏号 | 2-s2.0-85015940298 |
引用统计 | |
文献类型 | 会议论文 |
条目标识符 | https://repository.uic.edu.cn/handle/39GCC9TT/7236 |
专题 | 个人在本单位外知识产出 |
作者单位 | College of Computer Science and Technology, Huaqiao University, Xiamen, China |
推荐引用方式 GB/T 7714 | Kong, Xinling,Chen, Yonghong,Tian, Huiet al. A novel botnet detection method based on preprocessing data packet by graph structure clustering[C], 2017: 42-45. |
条目包含的文件 | 条目无相关文件。 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论