A c&c channel discrimination method and system
A discrimination method and channel technology, applied in the field of C&, can solve the problems of inability to distinguish, unfavorable regular retraining of discriminant models, timely deployment and deployment impact, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0071] Using the behavior characterization to classify the second network flow set to obtain the several original features.
[0074] Determine the NODNS IP address dispersion degree category, and set to obtain a pair of dstip attribute sets in a network flow set
[0075] Determine the NODNS port dispersion degree category, extract the TCP flow in the second network flow set, according to the TCP flow
[0076] Determine the NODNS scale dispersion degree category, extract the TCP flow and the UDP flow in the second network flow set, and calculate respectively
[0077] Determine the NODNS communication similarity category, and extract all of the second network flow sets with the same protocol
[0086] The fifth category is NODNS communication similarity: since the infected hosts in the same botnet will
[0088] W
[0089] The Type attribute represents the type of the C&C channel structure generated by the infected host in the time slot. When Wi is
[0096]
[0097] where p(x, y) is th...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


