Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and system for automatically identifying B/S botnet background, and storage medium

A botnet, automatic identification technology, applied in the field of automatic identification of B/S botnet background, can solve problems such as difficult and effective detection, and achieve the effect of high accuracy and fast identification speed

Active Publication Date: 2019-03-15
BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF5 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Among them, network security researchers have conducted a lot of research on botnets based on the IRC protocol, and there are many corresponding detection methods for them. Emerging botnets based on P2P protocols and HTTP protocols have gradually become popular, especially those based on HTTP protocols Botnets are hidden in massive HTTP communication traffic, making it difficult to detect them effectively

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for automatically identifying B/S botnet background, and storage medium
  • Method and system for automatically identifying B/S botnet background, and storage medium
  • Method and system for automatically identifying B/S botnet background, and storage medium

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0045] The present invention provides the embodiment of the method, system and storage medium of automatic identification B / S botnet background, in order to make those skilled in the art better understand the technical scheme in the embodiment of the present invention, and make the above-mentioned embodiment of the present invention The purpose, features and advantages can be more obvious and understandable, and the technical solution in the present invention will be further described in detail below in conjunction with the accompanying drawings:

[0046] The present invention at first provides a kind of method embodiment 1 of automatic identification B / S botnet background, as figure 1 shown, including:

[0047] S101: Obtain the URL of the website to be detected.

[0048] S102: Preprocessing the URL of the website to be detected.

[0049] Wherein, the preprocessing of the URL of the website to be detected includes: removing the file name and parameters in the URL of the webs...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and a system for automatically identifying a B / S botnet background, and a storage medium. The method comprises the following steps of acquiring a to-be-detected website URL; preprocessing the to-be-detected website URL; extracting a feature from a botnet background feature library, and judging the feature type; if the feature is a file name feature, carrying out crawling test on a to-be-detected website by utilizing the file name feature, if a webpage file corresponding to the file name feature exists, giving an alarm; and if the feature is a file content feature, traversing the to-be-detected website by utilizing the file content feature, and giving an alarm if matching is successful, wherein the file name feature and the file content feature which are extracted from the known botnet background are stored in the botnet background feature library. According to the method and the system for automatically identifying the B / S botnet background, and the storage medium, the botnet background of a B / S framework based on an HTTP can be effectively identified.

Description

technical field [0001] The invention relates to the technical field of network security, in particular to a method, system and storage medium for automatically identifying the background of a B / S botnet. Background technique [0002] Botnet is a kind of network with great harm at present. It is controlled by botnet to infect other computers by spreading malicious software, and then centrally manages and controls these computers through a C&C server. A one-to-many controllable network is formed between the botnet controller and the infected host. The malicious software used by the botnet controller to infect the victim host can interact with the C&C server to execute the tasks issued by the C&C server. By using this attack platform composed of botnets, attackers can complete large-scale network attacks with low cost and resources, such as launching distributed denial of service attacks (DDOS), sending spam, obtaining sensitive information, distributing Trojan horses and spyw...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): H04L12/24H04L29/06
CPCH04L41/0631H04L63/1416H04L63/1441H04L63/30
Inventor 刘佳男王文辉李柏松王小丰
Owner BEIJING ANTIY NETWORK SAFETY TECH CO LTD
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More