A method for tracking a backbone network botnet based on a distributed space-time mechanism
A botnet, distributed technology, applied in the field of backbone network botnet tracking based on distributed space-time mechanism, to avoid passivation
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0020] The structure of this patent application is as follows figure 1 As shown, it includes network traffic probe, macro distribution feature extraction engine, IP classifier, distributed mechanism discrimination engine, DNS anomaly detection engine, DNS whitelist, Fast Flux DNS detection module, secondary probe, and access behavior iterator.
[0021] The working steps of the backbone network botnet tracking method in the network security field described in this patent application are as follows:
[0022] (1) The traffic probe sends the DNS data in the traffic to the DNS abnormal traffic detection engine, which uses the whitelist to filter and then sends the DNS access data to the Fast Flux DNS detection module to detect domain names with Fast Flux DNS features;
[0023] (2) The traffic probe sends the TCP handshake message and end message in the traffic to the macro distribution feature extraction engine to obtain the IP address data represented by the macro distribution fe...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 
