CN103916288A - 一种基于网关与本地的Botnet检测方法及系统 - Google Patents
一种基于网关与本地的Botnet检测方法及系统 Download PDFInfo
- Publication number
- CN103916288A CN103916288A CN201310734546.5A CN201310734546A CN103916288A CN 103916288 A CN103916288 A CN 103916288A CN 201310734546 A CN201310734546 A CN 201310734546A CN 103916288 A CN103916288 A CN 103916288A
- Authority
- CN
- China
- Prior art keywords
- network packet
- network
- think
- botnet
- main frame
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 36
- 238000012544 monitoring process Methods 0.000 claims abstract description 75
- 238000000034 method Methods 0.000 claims abstract description 29
- 230000002123 temporal effect Effects 0.000 claims description 25
- 239000012634 fragment Substances 0.000 claims description 16
- 230000008569 process Effects 0.000 claims description 13
- 238000005516 engineering process Methods 0.000 abstract description 12
- 238000010276 construction Methods 0.000 abstract description 2
- 230000006399 behavior Effects 0.000 abstract 1
- 235000012907 honey Nutrition 0.000 abstract 1
- 150000001875 compounds Chemical class 0.000 description 3
- 241001269238 Data Species 0.000 description 2
- 238000007792 addition Methods 0.000 description 2
- 238000007796 conventional method Methods 0.000 description 2
- 230000007812 deficiency Effects 0.000 description 2
- 238000012217 deletion Methods 0.000 description 2
- 230000037430 deletion Effects 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 206010000117 Abnormal behaviour Diseases 0.000 description 1
- 241000700605 Viruses Species 0.000 description 1
- 230000008901 benefit Effects 0.000 description 1
- 230000015556 catabolic process Effects 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 239000012141 concentrate Substances 0.000 description 1
- 230000008878 coupling Effects 0.000 description 1
- 238000010168 coupling process Methods 0.000 description 1
- 238000005859 coupling reaction Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 239000012636 effector Substances 0.000 description 1
- 230000007613 environmental effect Effects 0.000 description 1
- 230000003203 everyday effect Effects 0.000 description 1
- 238000012423 maintenance Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000003012 network analysis Methods 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 201000007094 prostatitis Diseases 0.000 description 1
- 238000004088 simulation Methods 0.000 description 1
- 201000009032 substance abuse Diseases 0.000 description 1
- 230000009885 systemic effect Effects 0.000 description 1
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310734546.5A CN103916288B (zh) | 2013-12-27 | 2013-12-27 | 一种基于网关与本地的Botnet检测方法及系统 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310734546.5A CN103916288B (zh) | 2013-12-27 | 2013-12-27 | 一种基于网关与本地的Botnet检测方法及系统 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN103916288A true CN103916288A (zh) | 2014-07-09 |
| CN103916288B CN103916288B (zh) | 2017-11-28 |
Family
ID=51041706
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201310734546.5A Active CN103916288B (zh) | 2013-12-27 | 2013-12-27 | 一种基于网关与本地的Botnet检测方法及系统 |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN103916288B (zh) |
Cited By (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105260662A (zh) * | 2014-07-17 | 2016-01-20 | 南京曼安信息科技有限公司 | 一种未知应用漏洞威胁检测装置及方法 |
| CN105516164A (zh) * | 2015-12-22 | 2016-04-20 | 中国科学院长春光学精密机械与物理研究所 | 基于分形与自适应融合的P2P botnet检测方法 |
| CN106060025A (zh) * | 2016-05-24 | 2016-10-26 | 北京奇虎科技有限公司 | 应用程序的自动分类方法和装置 |
| CN106101061A (zh) * | 2016-05-24 | 2016-11-09 | 北京奇虎科技有限公司 | 恶意程序的自动分类方法和装置 |
| CN106657100A (zh) * | 2016-12-29 | 2017-05-10 | 哈尔滨安天科技股份有限公司 | 一种基于数据包过滤的远程控制恶意程序检测方法及系统 |
| CN110225064A (zh) * | 2019-07-02 | 2019-09-10 | 恒安嘉新(北京)科技股份公司 | 监测僵尸网络攻击行为的方法、装置、设备和存储介质 |
| CN110795730A (zh) * | 2018-10-23 | 2020-02-14 | 北京安天网络安全技术有限公司 | 一种恶意文件彻底清除方法、系统及存储介质 |
| US20210092142A1 (en) * | 2016-02-25 | 2021-03-25 | Imperva, Inc. | Techniques for targeted botnet protection |
| TWI729320B (zh) * | 2018-11-01 | 2021-06-01 | 財團法人資訊工業策進會 | 可疑封包偵測裝置及其可疑封包偵測方法 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101360019A (zh) * | 2008-09-18 | 2009-02-04 | 华为技术有限公司 | 一种僵尸网络的检测方法、系统和设备 |
| CN101404658A (zh) * | 2008-10-31 | 2009-04-08 | 北京锐安科技有限公司 | 一种检测僵尸网络的方法及其系统 |
| CN102333313A (zh) * | 2011-10-18 | 2012-01-25 | 中国科学院计算技术研究所 | 移动僵尸网络特征码生成方法和移动僵尸网络检测方法 |
| WO2012015485A1 (en) * | 2010-07-28 | 2012-02-02 | Mcafee, Inc. | System and method for local protection against malicious software |
-
2013
- 2013-12-27 CN CN201310734546.5A patent/CN103916288B/zh active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101360019A (zh) * | 2008-09-18 | 2009-02-04 | 华为技术有限公司 | 一种僵尸网络的检测方法、系统和设备 |
| CN101404658A (zh) * | 2008-10-31 | 2009-04-08 | 北京锐安科技有限公司 | 一种检测僵尸网络的方法及其系统 |
| WO2012015485A1 (en) * | 2010-07-28 | 2012-02-02 | Mcafee, Inc. | System and method for local protection against malicious software |
| CN102333313A (zh) * | 2011-10-18 | 2012-01-25 | 中国科学院计算技术研究所 | 移动僵尸网络特征码生成方法和移动僵尸网络检测方法 |
Non-Patent Citations (1)
| Title |
|---|
| 丁晓江: "基于机网联合的P2P Bot检测方法的研究与实现", 《中国优秀硕士学位论文全文数据库(电子期刊)信息科技辑》 * |
Cited By (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105260662A (zh) * | 2014-07-17 | 2016-01-20 | 南京曼安信息科技有限公司 | 一种未知应用漏洞威胁检测装置及方法 |
| CN105516164A (zh) * | 2015-12-22 | 2016-04-20 | 中国科学院长春光学精密机械与物理研究所 | 基于分形与自适应融合的P2P botnet检测方法 |
| CN105516164B (zh) * | 2015-12-22 | 2018-11-27 | 中国科学院长春光学精密机械与物理研究所 | 基于分形与自适应融合的P2P botnet检测方法 |
| US20210092142A1 (en) * | 2016-02-25 | 2021-03-25 | Imperva, Inc. | Techniques for targeted botnet protection |
| CN106060025A (zh) * | 2016-05-24 | 2016-10-26 | 北京奇虎科技有限公司 | 应用程序的自动分类方法和装置 |
| CN106101061A (zh) * | 2016-05-24 | 2016-11-09 | 北京奇虎科技有限公司 | 恶意程序的自动分类方法和装置 |
| CN106657100A (zh) * | 2016-12-29 | 2017-05-10 | 哈尔滨安天科技股份有限公司 | 一种基于数据包过滤的远程控制恶意程序检测方法及系统 |
| CN110795730A (zh) * | 2018-10-23 | 2020-02-14 | 北京安天网络安全技术有限公司 | 一种恶意文件彻底清除方法、系统及存储介质 |
| TWI729320B (zh) * | 2018-11-01 | 2021-06-01 | 財團法人資訊工業策進會 | 可疑封包偵測裝置及其可疑封包偵測方法 |
| US11057403B2 (en) | 2018-11-01 | 2021-07-06 | Institute For Information Industry | Suspicious packet detection device and suspicious packet detection method thereof |
| CN110225064A (zh) * | 2019-07-02 | 2019-09-10 | 恒安嘉新(北京)科技股份公司 | 监测僵尸网络攻击行为的方法、装置、设备和存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103916288B (zh) | 2017-11-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN103916288A (zh) | 一种基于网关与本地的Botnet检测方法及系统 | |
| Nawrocki et al. | A survey on honeypot software and data analysis | |
| US10362057B1 (en) | Enterprise DNS analysis | |
| US9838426B2 (en) | Honeyport active network security | |
| US20230115046A1 (en) | Network security system for preventing unknown network attacks | |
| KR101070614B1 (ko) | 봇넷 정보를 이용한 악성 트래픽 격리 시스템과 봇넷 정보를 이용한 악성 트래픽 격리 방법 | |
| US9432389B1 (en) | System, apparatus and method for detecting a malicious attack based on static analysis of a multi-flow object | |
| KR100800370B1 (ko) | 어택 서명 생성 방법, 서명 생성 애플리케이션 적용 방법, 컴퓨터 판독 가능 기록 매체 및 어택 서명 생성 장치 | |
| Verba et al. | Idaho national laboratory supervisory control and data acquisition intrusion detection system (SCADA IDS) | |
| CN103561004B (zh) | 基于蜜网的协同式主动防御系统 | |
| US20170289191A1 (en) | Infiltration Detection and Network Rerouting | |
| EP3108401B1 (en) | System and method for detection of malicious hypertext transfer protocol chains | |
| US20220263823A1 (en) | Packet Processing Method and Apparatus, Device, and Computer-Readable Storage Medium | |
| WO2017131963A1 (en) | Using high-interaction networks for targeted threat intelligence | |
| CN107204965B (zh) | 一种密码破解行为的拦截方法及系统 | |
| CN104363240A (zh) | 基于信息流行为合法性检测的未知威胁的综合检测方法 | |
| US20240114052A1 (en) | Network security system for preventing spoofed ip attacks | |
| US20250384131A1 (en) | Ensemble intrusion detection system for iot platforms | |
| CN121098558A (zh) | 基于人工智能网络安全分析预警系统 | |
| Ponomarev | Intrusion Detection System of industrial control networks using network telemetry | |
| RU2703329C1 (ru) | Способ обнаружения несанкционированного использования сетевых устройств ограниченной функциональности из локальной сети и предотвращения исходящих от них распределенных сетевых атак | |
| CN112152972A (zh) | 检测iot设备漏洞的方法和装置、路由器 | |
| CN104113841B (zh) | 一种针对移动互联网Botnet的虚拟化检测系统及检测方法 | |
| CN118400201B (zh) | 基于硬件加速的恶意流量检测与防护方法、装置及系统 | |
| Mihanjo et al. | Isolation of DDoS Attacks and Flash Events in Internet Traffic Using Deep Learning Techniques |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| CP03 | Change of name, title or address | ||
| CP03 | Change of name, title or address |
Address after: 150010 Heilongjiang science and technology innovation city, Harbin new and high tech Industrial Development Zone, No. 7 building, innovation and entrepreneurship Plaza, 838 Patentee after: Harbin Antian Science and Technology Group Co.,Ltd. Address before: 150090 room 506, Hongqi Street, Nangang District, Harbin Development Zone, Heilongjiang, China, 162 Patentee before: HARBIN ANTIY TECHNOLOGY Co.,Ltd. |
|
| TR01 | Transfer of patent right | ||
| TR01 | Transfer of patent right |
Effective date of registration: 20180613 Address after: 518000 Shenzhen, Baoan District, Guangdong Xixiang Baoan District street, the source of excellent industrial products display procurement center, block B, 7 floor, No. Patentee after: SHENZHEN ANZHITIAN INFORMATION TECHNOLOGY Co.,Ltd. Address before: 150010 Heilongjiang science and technology innovation city, Harbin new and high tech Industrial Development Zone, No. 7 building, innovation and entrepreneurship Plaza, 838 Patentee before: Harbin Antian Science and Technology Group Co.,Ltd. |
|
| CP01 | Change in the name or title of a patent holder | ||
| CP01 | Change in the name or title of a patent holder |
Address after: 518000 Shenzhen, Baoan District, Guangdong Xixiang Baoan District street, the source of excellent industrial products display procurement center, block B, 7 floor, No. Patentee after: Shenzhen Antan Network Security Technology Co.,Ltd. Address before: 518000 Shenzhen, Baoan District, Guangdong Xixiang Baoan District street, the source of excellent industrial products display procurement center, block B, 7 floor, No. Patentee before: SHENZHEN ANZHITIAN INFORMATION TECHNOLOGY Co.,Ltd. |