System and method for detecting IRC bot network based on data packet sequence characteristics
A botnet and data packet technology, applied in digital transmission systems, transmission systems, electrical components, etc., can solve the problems of periodic small-scale changes of data packets, disordered data packets, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0029] see figure 1 As shown, an IRC botnet detection system based on data packet sequence features is composed of four parts: offline basic data extraction module, online data real-time analysis module, data center and detection strategy control module.
[0030] The offline basic data extraction module is responsible for the protocol offline of the TCP traffic (including the content of the data packet) of the monitored network egress traffic mirror, using the key feature fields of the IRC protocol such as NICK, USER, PASSWORD, PRIVMSG, PUBMSG, NOTICE, etc. Content matching to identify and discover the IP address and port of the server based on the IRC protocol, write this information into the data center, establish the IP address and port database of the IRC server, and provide basic data preparation for the online data real-time analysis module.
[0031] The online data real-time analysis module is responsible for online real-time analysis of IRC botnet command and control (...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 