Method and system for detecting bot network
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- RUN TECH CO LTD BEIJING
- Publication Date
- 2009-04-08
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2
Abstract
Description
Technical field:
[0001] The technology belongs to the field of computer security, specifically a method and system for detecting and finding the existence of botnets in the Internet. Background technique:
[0002] Botnet refers to the use of one or more means of propagation to infect a large number of hosts with bot programs (bots), thereby forming a one-to-many controllable network between the controller and the infected hosts.
[0003] There are several keywords in the concept of botnets. "Bot program" is the abbreviation of robot, which refers to the program code to realize the malicious control function; "zombie computer" is the computer implanted with bot; "Controller computer" refers to a computer that remotely controls the zombie computer by sending instructions to the control server, and the control server forwards these instructions to the zombie computer. Most botnets are botnets controlled based on the IRC (Internet Relay Chat) protocol, and botnets controlled t...