首頁瀏覽人次: 698,428 次 (Since 2010/07/14) 會員登入
聯盟單位  |  虛擬講堂  |  網路直播  |  其他演講  |  排行榜  |  留言板  |  知識擂台  |  回首頁
首頁 > 虛擬講堂 > DGA-based Botnet Detection Using Bigram Analysis of Domain Names 快速搜尋演講 進階搜尋
  DGA-based Botnet Detection Using Bigram Analysis of Domain Names 
★chrome瀏覽器無法播放Silverlight解決辦法
0:00 / 0:00

講者:國立成功大學 王子夏
日期:2015/10/21
性質:演講
類別:應用科學
語言:中文
長度:00:17:28
觀看:354
推薦:0
摘要:
Session F2:資通安全及個人資料安全保護管理

論文作者:Ho-Chuan Hoh, Tzy-Shiah Wang, Hui-Tang Lin

Botnets are one of the major current threats ...
Session F2:資通安全及個人資料安全保護管理

論文作者:Ho-Chuan Hoh, Tzy-Shiah Wang, Hui-Tang Lin

Botnets are one of the major current threats to network security. A botnet is able to launch attacks such as information stealing, phishing site, spam mails and distributed denial of service (DDoS). Some botnets called Domain Generation Algorithm (DGA) Botnets apply a domain generation algorithm to avoid being detected by the traditional blacklist detection scheme. Using a domain generation algorithm, a huge list of candidate command and control server (C&C) domains are generated periodically. A bot then attempts to connect to the C&C server by querying DNS servers in the domain on the list one-by-one until it connects to an existing C&C server. By doing this, DGA bonnets are very elusive and difficult to detect by traditional defensive systems and thus have high survivability. To resolve this issue, this approach proposes a DGA-based botnet detection system based on the analysis of the distribution of alphanumeric characters in the DNS traffic. The system consists of three group detection algorithms to capture the Botnet groups. Our experiments show our system achieves very high performance. During our experiments, we captured one known DGA-based botnet and one new DGA-based botnet in our monitoring network environment. This shows that the proposed scheme is able to accurately and effectively detect and analyze DGA-based botnets.

現在位置:演講摘要詳細內容
推薦  (0)
推薦至Plurk
提供:TANET台灣網際網路研討會-TANET2015

轉寄  

推薦者:
電子郵件地址: (如欲轉寄多人,請以 ; 分隔email)
留言給收件者:

回報問題  

問題說明:




植基於檔案異動行為建模與備援...
講者:莊般若, 王子夏...
觀看:138
基於小型物聯網之遠端照明控制...
講者:鄧博謙, 詹子寬...
觀看:113
減輕無線感測網路樹狀路由的單...
講者:王郁傑
觀看:747
A Fixed-Stride...
講者:趙啟時
觀看:433
【週日閱讀科學大師】通往宇宙...
講者:吳俊輝
觀看:79
【週日閱讀科學大師】上太空也...
講者:黃居正
觀看:74

現在位置:學習公約