A method for judging the authenticity of zombie Trojans on the Internet

By constructing a zombie Trojan information granularity model based on multiple attribute factors, the authenticity of the zombie Trojan can be quickly and accurately judged, solving the problems of high false alarm rate and low efficiency in zombie Trojan judgment in the existing technology, and realizing efficient zombie Trojan event analysis.

CN116633619BActive Publication Date: 2025-09-30NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT HENAN BRANCH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310592726.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-24
Publication Date
2025-09-30
Estimated Expiration
2043-05-24

AI Technical Summary

Technical Problem

Existing methods for identifying zombie Trojans have high false positive rates, high manual verification costs, and low efficiency. They also rely on feature library matching, resulting in long detection times and making it difficult to efficiently handle zombie Trojan incidents.

Method used

By using time attribute function, source IP attribute function, destination IP attribute function, unit attribute function, event urgency attribute function and IP correlation attribute function, a single-granularity and multi-granularity level zombie Trojan information granularization model is constructed. Through granular computing and multi-granularity rough set theory, the authenticity of zombie Trojans can be quickly and accurately judged.

Benefits of technology

It improves the accuracy and efficiency of zombie and Trojan horse judgment, reduces the cost of manual verification, and realizes efficient analysis of zombie and Trojan horse incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116633619B_ABST
    Figure CN116633619B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for determining the authenticity of zombie Trojans on the Internet, comprising the following steps: A: obtaining a zombie Trojan dataset to be determined and determining the zombie Trojan attribute factors of the zombie Trojan data to be determined; B: constructing a zombie Trojan information granularity model at a single granularity level; C: constructing a zombie Trojan information granularity model at multiple granularity levels; D: making a judgment based on the coordination of decision attributes and selecting the optimal zombie Trojan judgment granularity; E: selecting a zombie Trojan information granularity model at a corresponding level based on the optimal zombie Trojan judgment granularity, and then determining the authenticity of the corresponding zombie Trojan data to be determined by querying the log information of the host corresponding to the controlled terminal IP in the destination IP attribute function. The present invention can effectively improve the accuracy and efficiency of zombie Trojan judgment and more efficiently support the analysis of zombie Trojan events.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet security, and in particular to a method for determining the authenticity of zombie Trojans on the Internet. Background Art

[0002] The vigorous development of the Internet is an inevitable condition for economic growth in an information-based society. As the scale of the Internet continues to expand and its structure becomes increasingly complex, the Internet brings huge economic benefits while also coexisting risks and challenges.

[0003] Currently, relying solely on passive defense measures such as intrusion prevention systems is no longer effective against bot attacks. Only by proactively monitoring, analyzing, alerting, and blocking bot incidents can the occurrence of network security incidents be effectively reduced. In recent years, system platforms specifically designed for bot incident monitoring have emerged. While most monitoring platforms can effectively handle bot incidents, they still experience a certain rate of false positives, requiring manual verification of the accuracy of bot incident reports provided by the system before informing the relevant authorities for coordinated investigation and resolution. This process has numerous drawbacks, including long lead times, high verification costs, and low efficiency. Furthermore, verification requires manual downloading of detailed bot incident information, a process that varies depending on the search criteria. Longer time intervals in the search criteria increase download times, limiting its ability to handle real-time incidents.

[0004] Currently, identifying botnets primarily relies on matching network data flows with signature libraries. Existing methods are mostly based on attack data analysis. For example, they analyze the dynamic characteristics of network data flows or extract and analyze botnet attack data based on collected network attack packets. Other methods can identify botnets by analyzing network traffic, for example, extracting feature vectors from each packet and analyzing all packets in a session to analyze the botnet's communication behavior. Alternatively, statistical features can be extracted from data flows at different communication stages of a remote control bot, using ensemble learning to identify remote control bot traffic. Because these methods analyze all packets, they require significant matching and identification time. As the volume of detection data increases, so does the time required to match the signature library.

[0005] For example, the Chinese invention patent application number 201811025294.8, filed on September 4, 2018, entitled "Method, Device, and Storage Medium for Actively Detecting IoT Botnet Trojans," discloses a method for actively detecting IoT botnet Trojans. The method uses the control node information of known IoT botnet Trojans to extract corresponding script file names as a script name dictionary set; actively performs full-port scanning on high-frequency IP segments to obtain and filter fingerprint information of important ports; based on the script name dictionary set, automatically guesses the target port with important fingerprint information through blind infection scripts; extracts the Trojan download link stored in the automated infection script for the automated infection script obtained through blind guessing; downloads the Trojan according to the Trojan download link, detects and identifies the Trojan, and classifies the Trojan to provide information for subsequent Trojan monitoring. The above technical solution uses the automated infection script obtained through blind guessing from the script name dictionary set, and then extracts the Trojan download link. Therefore, it can be seen that the enrichment of the script name dictionary set directly affects the extraction effect of the Trojan download link. However, since the number of script names in the current dictionary set is limited and each additional entry requires a lot of manpower and material resources, the above technical solution cannot effectively process zombie Trojan horse events in batches and has the disadvantage of low efficiency.

[0006] With the increasing number of zombie Trojan types and zombie Trojan incidents, the uncertainty, difficulty and time of judging the authenticity of zombie Trojans have increased, and new judgment methods are urgently needed. Summary of the Invention

[0007] The purpose of the present invention is to provide a method for determining the authenticity of zombie Trojans on the Internet, which can effectively improve the accuracy and efficiency of zombie Trojan judgment and more efficiently support the analysis of zombie Trojan events.

[0008] The present invention adopts the following technical solutions:

[0009] A method for determining the authenticity of a zombie Trojan horse on the Internet comprises the following steps in sequence:

[0010] A: Obtain a dataset of zombie Trojans to be determined and determine the zombie Trojan attribute factors of the zombie Trojan data to be determined;

[0011] Among them, the zombie Trojan attribute factors include time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), unit attribute function f4(x), event urgency attribute function f5(x) and IP correlation attribute function f6(x); time attribute function f1(x) includes the suspected controlled time of the zombie Trojan data to be determined, source IP attribute function f2(x) includes the control end IP and the control end port; destination IP attribute function f3(x) includes the controlled end IP and the controlled end port; unit attribute function f4(x) includes the controlled IP affiliation and the destination IP affiliation; event urgency attribute function f5(x) is the different urgency levels set in descending order according to the reporting time of the zombie Trojan data to be determined; IP correlation attribute function f6(x) is the matching rate between the real zombie Trojan data and the control end IP address of the zombie Trojan data to be determined;

[0012] B: Using the multiple zombie Trojan attribute factors obtained in step A, based on granular computing theory, a single-granularity level zombie Trojan information granular model is constructed. Among them, U represents the object, C represents the condition attribute, and d represents the decision attribute;

[0013] C: Using the time attribute function f1(x) obtained in step A and the single-granularity level zombie Trojan information granulation model BDM constructed in step B, based on the multi-granularity rough set theory, the domain U is divided by the attribute method, and according to the event urgency f5(x) of the zombie Trojan data to be determined, the multi-granularity level zombie Trojan information granulation model is constructed in sequence. Among them, the domain U is the object U, T represents the time granularity, k represents the number of layers of the granularity model, C represents the conditional attribute, and d represents the decision attribute;

[0014] D: Zombie Trojan Information Granularization Model (BDM) from multiple granularity levels k In the process, the optimal zombie Trojan judgment granularity is selected based on the coordination of decision attributes;

[0015] E: Select the zombie information granularity model of the corresponding level based on the optimal zombie judgment granularity obtained in step D, and then judge the authenticity of the corresponding zombie data by querying the log information of the host corresponding to the controlled IP in the destination IP attribute function f3(x).

[0016] Described step A comprises the following steps:

[0017] A1: Obtain a dataset of zombie Trojans to be identified;

[0018] A2: Using the zombie Trojan data set to be determined, obtain the time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), and unit attribute function f4(x) of the zombie Trojan data to be determined;

[0019] A3: Using the unidentified zombie Trojan data set, the event urgency attribute function f5(x) of the corresponding unidentified zombie Trojan data is set to different urgency levels in descending order according to the reporting time of the unidentified zombie Trojan data. The time priority processing order is descending.

[0020] A4: Construct a real zombie Trojan data set, and calculate the matching rate of the control end IP address for the real zombie Trojan data in the real zombie Trojan data set and the zombie Trojan data to be determined in the zombie Trojan data set. The IP address matching rate is obtained as the IP correlation attribute function f6(x) of the zombie Trojan data to be determined.

[0021] The calculation method of the IP address matching rate in step A4 is as follows:

[0022] A41: Construct a real zombie Trojan data set consisting of real zombie Trojan data;

[0023] A42: Convert the IP addresses of the control end of the real zombie Trojan data in the real zombie Trojan data set into integers in sequence, and finally obtain the integer representation IP1 of the IP address of the control end of the real zombie Trojan data;

[0024] A43: According to the method of step A42, obtain the integer representation IP2 of the control terminal IP address of the zombie Trojan data to be determined in the zombie Trojan data set to be determined;

[0025] A44: Calculate the IP address matching ratio of the control end IP addresses of the real zombie Trojan data, represented by the integer type IP1, and the control end IP address of the zombie Trojan data to be determined, represented by the integer type IP2, to obtain the corresponding IP address matching ratio R.

[0026]

[0027] Among them, IP0 is the set IP address deviation range threshold.

[0028] In the step C, the granular model of zombie information at the single granularity level On this basis, let the total granularity level of the construction be I, and construct it layer by layer from fine to coarse. The attribute set of each layer is recorded as The specific steps include:

[0029] C1: Zombie Trojan Information Granularity Model at a Single Granularity Level On this basis, let the time granularity T be in seconds to obtain the first-level zombie Trojan information granularity model

[0030] C2: Zombie Trojan Information Granularity Model at a Single Granularity Level On this basis, when the time granularity T is taken as a unit of minutes, the second-level zombie Trojan information granularity model is obtained

[0031] C3: Zombie Trojan Information Granularity Model at a Single Granularity Level On this basis, when the time granularity T is taken as the unit of time, the third-level zombie Trojan information granular model is obtained

[0032] Finally, we obtain three different levels of granularity of zombie Trojan information granularity models BDM 1 , BDM 2 and BDM 3 , and obtain the decision attribute set of different zombie Trojan data to be determined at the corresponding granularity level

[0033] In the above step D, when judging based on the coordination of decision attributes, the multi-granularity level zombie Trojan information granular model 1≤k≤I, if Then the zombie Trojan information granulation model is called coordinated, otherwise it is called inconsistent;

[0034] Among them, R d is the decision attribute set of real zombie Trojan data, R T It is the decision attribute set of the zombie Trojan data to be determined.

[0035] In the above step E, when determining the authenticity of the zombie Trojan data to be determined, if the attribute factor of the zombie Trojan data to be determined meets any one of the following conditions, then the zombie Trojan data to be determined is determined to be authentic zombie Trojan data; otherwise, it is not authentic zombie Trojan data;

[0036] Condition 1: The time attribute function f1(x) of the zombie Trojan data to be determined, that is, the suspected controlled time of the zombie Trojan data to be determined is within the set time range; where the time range is (t x -t b , t x +t b ), t x represents the controlled time of the real zombie Trojan data that is closest to the suspected controlled time f1(x) of the zombie Trojan data to be determined and has the same controlled end IP address, t b is the set time threshold;

[0037] Condition 2: The IP correlation attribute function f6(x) of the zombie Trojan data to be determined, that is, the IP address matching rate R between the real zombie Trojan data in the zombie Trojan real data set and the zombie Trojan data to be determined is greater than or equal to the set matching threshold R b .

[0038] Also comprising step F;

[0039] F: Put the undetermined zombie Trojan data that has been determined to be real zombie Trojan data in step E into the zombie Trojan real data set, and update the zombie Trojan real data set.

[0040] In step A42, each segment of the control end IP address of the real zombie Trojan data is treated as an integer from 0 to 255, and then each segment of the control end IP address that has been converted into an integer is converted into binary form to obtain a corresponding binary number, and finally the obtained binary number is converted into a long integer, and finally the integer representation IP1 of the control end IP address of the real zombie Trojan data is obtained.

[0041] For the multi-level granularity model of zombie Trojan information The time granularity T in seconds is selected as the optimal time granularity.

[0042] The time threshold is 10 minutes; the matching threshold R b The value is 0.

[0043] The present invention uses time attribute function, source IP attribute function, destination IP attribute function, unit attribute function, event urgency attribute function and IP correlation attribute function to represent the different attributes of zombie Trojans from multiple aspects. These multiple attributes are then used to jointly construct a multi-granularity zombie Trojan information granularization model in subsequent steps and apply it.

[0044] The present invention first constructs a single-granularity zombie Trojan information granularization model based on granular computing theory according to multiple zombie Trojan attribute factors; on this basis, the time attribute function is used and based on the multi-granularity rough set theory, the domain is divided through the attribute method, and according to the event urgency of the zombie Trojan data to be determined, the multi-granularity zombie Trojan information granularization model is constructed in sequence, and finally the optimal time granularity is determined quickly and accurately according to the coordination of decision attributes; the present invention also uses the time attribute function and the IP correlation attribute function through specially set judgment rules to judge the authenticity of zombie Trojans, which can effectively improve the accuracy and efficiency of zombie Trojan judgment and more efficiently support the analysis of zombie Trojan events. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION

[0046] The present invention is described in detail below with reference to the accompanying drawings and embodiments:

[0047] like Figure 1 As shown, the method for determining the authenticity of zombie Trojans on the Internet according to the present invention includes the following steps:

[0048] A: Obtain a dataset of zombie Trojans to be determined and determine the zombie Trojan attribute factors of the zombie Trojan data to be determined;

[0049] Among them, the zombie Trojan attribute factors include time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), unit attribute function f4(x), event urgency attribute function f5(x) and IP correlation attribute function f6(x); time attribute function f1(x) includes the suspected controlled time of the zombie Trojan data to be determined, source IP attribute function f2(x) includes the control end IP and the control end port; destination IP attribute function f3(x) includes the controlled end IP and the controlled end port; unit attribute function f4(x) includes the controlled IP affiliation and the destination IP affiliation; event urgency attribute function f5(x) is the different urgency levels set in descending order according to the reporting time of the zombie Trojan data to be determined; IP correlation attribute function f6(x) is the matching rate between the real zombie Trojan data and the control end IP address of the zombie Trojan data to be determined;

[0050] In the present invention, the step A comprises the following specific steps:

[0051] A1: Obtain a dataset of zombie Trojans to be identified;

[0052] The zombie Trojan data set to be determined can be retrieved through the existing zombie Trojan event monitoring system platform; the zombie Trojan data set to be determined is composed of zombie Trojan data to be determined;

[0053] A2: Using the zombie Trojan data set to be determined, obtain the time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), and unit attribute function f4(x) of the zombie Trojan data to be determined;

[0054] A3: Using the unidentified zombie Trojan data set, the event urgency attribute function f5(x) of the corresponding unidentified zombie Trojan data is set to different urgency levels in descending order according to the reporting time of the unidentified zombie Trojan data. The time priority processing order is descending.

[0055] In this invention, the reporting time of bot data is a key attribute for determining bot authenticity and an important indicator for determining the urgency of a bot incident. If the reporting time exceeds one year, the bot data may have been processed, with limited reference value and low timeliness. Therefore, when determining the authenticity of a bot, the closer the bot was reported to the current time, the smaller the impact and the more valuable it is to address.

[0056] In the present invention, assuming that the current time is t0 and the reporting time of the zombie Trojan data to be determined is t1, if (t0-t1)≤90 days, it means that the reporting time of the zombie Trojan data to be determined is no more than 3 months ago, so the urgency of the zombie Trojan data to be determined is a particularly urgent event, and f5(x) is level IV; if 90 days < (t0-t1)≤180 days, it means that the reporting time of the zombie Trojan data to be determined is 3 months to half a year ago, so the urgency of the zombie Trojan data to be determined is a major urgent event, and f5(x) is level III; if 180 days < (t0-t1)≤270 days, it means that the zombie Trojan data to be determined is a serious urgent event. If the pending zombie Trojan data was reported between six months and nine months ago, the urgency of the pending zombie Trojan data is considered a relatively urgent event, and f5(x) is Level II. If 270 days < (t0-t1) ≤ 360 days, the pending zombie Trojan data was reported between nine months and one year ago, and the urgency of the pending zombie Trojan data is considered a moderately urgent event, and f5(x) is Level I. If 360 days < (t0-t1), the pending zombie Trojan data was reported more than one year ago, and the urgency of the pending zombie Trojan data is considered a normal event, and f5(x) is recorded as Level O.

[0057] In summary, the event urgency f5(x) of the corresponding zombie Trojan data to be determined is calculated through step A3, and the event priority processing order is level IV > level III > level II > level I > level O, so as to ensure that the authenticity judgment of the zombie Trojan event is more realistic.

[0058] A4: Construct a real zombie Trojan data set, and calculate the matching rate of the control end IP address for each of the real zombie Trojan data in the real zombie Trojan data set and the zombie Trojan data to be determined in the zombie Trojan data set. The IP address matching rate is used as the IP correlation attribute function f6(x) of the zombie Trojan data to be determined.

[0059] In the present invention, the IP correlation degree can reflect the similarity of the control end IP addresses of multiple zombie Trojan data. The higher the similarity, the more it indicates that the control end IP addresses of the above-mentioned multiple zombie Trojan data are in the same local area network, which is very likely to be a small-scale network formed by a department. It can serve as an important basis for judging the authenticity of zombie Trojans.

[0060] In the present invention, the calculation method of the IP address matching rate is as follows:

[0061] A41: Construct a real zombie Trojan data set consisting of real zombie Trojan data;

[0062] The real zombie Trojan data set can be composed of real data that has been confirmed to be from the same batch of zombie Trojans; or real zombie Trojan data sets that have been directly obtained from existing professional network information security websites. In the present invention, after each zombie Trojan authenticity determination, the data that has been determined to be zombie Trojans is added to the real zombie Trojan data set, so that the real zombie Trojan data set is continuously updated.

[0063] A42: Convert the IP addresses of the control end of the real zombie Trojan data in the real zombie Trojan data set into integers in sequence, and finally obtain the integer representation IP1 of the IP address of the control end of the real zombie Trojan data;

[0064] In step A42, each segment of the control end IP address of the real zombie Trojan data is treated as an integer from 0 to 255, and then each segment of the control end IP address converted to integer is converted into binary form to obtain a corresponding binary number, and finally the obtained binary number is converted into a long integer, and finally the integer representation IP1 of the control end IP address of the real zombie Trojan data is obtained;

[0065] A43: According to the method of step A42, obtain the integer representation IP2 of the control terminal IP address of the zombie Trojan data to be determined in the zombie Trojan data set to be determined;

[0066] A44: Calculate the IP address matching ratio of the control end IP addresses of the real zombie Trojan data, represented by the integer type IP1, and the control end IP address of the zombie Trojan data to be determined, represented by the integer type IP2, to obtain the corresponding IP address matching ratio R.

[0067]

[0068] Wherein, IP0 is a set IP address deviation range threshold, which is used to quantitatively represent the reasonable range of the difference between IP1 and IP2 when the IP addresses are similar (forming a local area network). In this embodiment, IP0 is set to 50.

[0069] In the present invention, the zombie attribute factors f1(x) to f6(x) can represent the different attributes of the zombie from multiple aspects, and the above different attributes can be used together to construct and apply a multi-granularity zombie information granular model in subsequent steps; in addition, the IP correlation attribute function f6(x) can also be used alone as one of the criteria for judging the authenticity of the zombie in subsequent steps.

[0070] B: Using the multiple zombie Trojan attribute factors obtained in step A, based on granular computing theory, a single-granularity level zombie Trojan information granular model is constructed.

[0071] Among them, U represents the object, U={x1,x2,…,x n} represent the first to nth zombie Trojan data to be determined; C represents the conditional attribute, C={a1,a2,…,a m} respectively represent the suspected controlled time, control end IP, control end port, controlled end IP, controlled end port, controlled IP ownership and destination IP ownership of the zombie Trojan data; d is the decision attribute, indicating the authenticity of the zombie Trojan event; object x i In attribute a j Take the unique granularity value above; 1≤i≤n, 1≤j≤m; Granular computing theory is a well-known technology in this field and will not be described in detail here;

[0072] In information systems, C is a conditional attribute, d is a decision attribute, and By adding decision attributes to the information system, a single-granularity level zombie Trojan information granular model can be constructed.

[0073] C: Using the time attribute function f1(x) obtained in step A and the single-granularity level zombie Trojan information granulation model BDM constructed in step B, based on the multi-granularity rough set theory, the domain U is divided by the attribute method, and according to the event urgency f5(x) of the zombie Trojan data to be determined, the multi-granularity level zombie Trojan information granulation model is constructed in sequence.

[0074] Wherein, the domain U is the object U, T represents the time granularity, and k represents the number of layers of the granularity model; the multi-granularity rough set theory is a well-known technology in this field and will not be described in detail here;

[0075] Prior art requires granularization before information granularity can be constructed to form a multi-granular information model. This process requires subjectively setting thresholds for various attributes within varying ranges. The information granular model must then be partitioned within these thresholds to ultimately form a multi-level granular model. However, in the process of constructing a multi-level bot and Trojan information granular model, the granularity partitioning criteria do not apply to all bot and Trojan attribute factors, significantly limiting existing granularity partitioning methods.

[0076] To address the above issues, the present invention uses an attribute method to divide the domain U. The domain U consists of all the zombie Trojan data to be determined in the zombie Trojan data set. The conditional attribute C is the multiple zombie Trojan attribute factors determined in step A, namely the time attribute function f1(x), the source IP attribute function f2(x), the destination IP attribute function f3(x), the unit attribute function f4(x), and the event urgency attribute function f5(x). In view of the attribute characteristics of zombie Trojans, in order to verify the authenticity of a zombie Trojan event to be determined in a relatively short period of time, the present invention uses the time attribute function f1(x) obtained in step A to divide the domain U. The initial time granularity of the domain U in the zombie Trojan monitoring system is seconds. In this embodiment, T is taken as three different granularity standards of seconds, minutes, and hours, and the domain U is fuzzy divided into {U(T)}, that is, ([U], [f], [T]) s 、([U],[f],[T]) m and ([U],[f],[T]) h Finally, according to the event urgency attribute function f5(x), a multi-level granularity model of zombie Trojan information is constructed. The subscript s represents seconds, the subscript m represents minutes, and the subscript h represents hours.

[0077] In the present invention, the zombie Trojan information granularity model at the single granularity level Based on this, let k represent the number of layers of the granularity model, I be the total number of granularity levels constructed, 1≤k≤I, if the object U takes a unique observation value at the time granularity T, then it is a single-granularity level zombie Trojan information granularity model BDM; if the object U takes observation values ​​of different scales at the time granularity T, then it is a multi-granularity level zombie Trojan information granularity model BDM k ; Due to BDM k The granularity level of the structure is k, and the granularity level structure is generally from fine-grained to coarse-grained, then the zombie Trojan judgment model of each layer is expressed as

[0078] Therefore, in the present invention, based on the single-granularity level zombie Trojan information granularization model, the total granularity level of the structure is set to I, and the structure is constructed layer by layer from fine to coarse, and the attribute set of each layer is recorded as Finally, we get a multi-level granularity model of zombie Trojan information.

[0079] Described step C comprises the following specific steps:

[0080] C1: Zombie Trojan Information Granularity Model at a Single Granularity Level On this basis, let the time granularity T be in seconds to obtain the first-level zombie Trojan information granularity model The decision attribute set of the zombie Trojan data to be determined at this time As shown in Table 1:

[0081] Table 1 First-layer zombie Trojan information granularity model

[0082]

[0083] Where U represents the object, x1 to x8 represent the first to eighth pieces of bot data to be determined, respectively; C represents the attribute, a1 to a7 represent the suspected controlled time, control end IP, control end port, controlled end IP, controlled end port, controlled IP ownership, and destination IP ownership of the bot data, respectively; d represents the decision attribute, "1" indicates that the data can be determined as a real bot event, and "0" indicates that the data cannot be determined as a real bot event.

[0084] C2: Therefore, when the time granularity T is taken as a unit of minutes, the second-level zombie Trojan information granular model can be obtained. The decision attribute set of the zombie Trojan data to be determined at this time As shown in Table 2.

[0085] Table 2 Second-layer zombie Trojan information granularity model

[0086]

[0087]

[0088] C3: Similarly, when the time granularity T is taken as the unit of time, the third-level zombie Trojan information granular model can be obtained. The decision attribute set of the zombie Trojan data to be determined at this time As shown in Table 3:

[0089] Table 3 Third-layer zombie Trojan information granularity model

[0090]

[0091] Analyzing Tables 1 to 3, assuming that x3, x5, and x7 are actually known to be real zombie Trojan data, the object U can be initially divided into {x3, x5, x7}{x1, x2, x4, x6, x8}, so the decision attribute set R of the real zombie Trojan data is d ={x3,x5,x7}, where x3, x5, and x7 are true, is represented by "1". In the example, the time granularity T is set in seconds, minutes and hours respectively, and three different granularity levels of zombie information granularity models BDM can be obtained. 1 , BDM 2 and BDM 3, thus obtaining different decision attribute sets as follows:

[0092] Object U 1 According to the decision attributes, it can be divided into {x1,x3,x4,x5,x7}{x2,x6,x8}, among which x1,x3,x4,x5,x7 are true;

[0093] R T2 ={1,0,1,0,1,0,1,0}, object U 2 According to the decision attributes, it can be divided into {x1,x3,x5,x7}{x2,x4,x6,x8}, among which x1,x3,x5,x7 are true;

[0094] R T3 ={0,0,1,0,1,0,1,0}, object U 3 According to the decision attributes, it can be divided into {x3,x5}{x1,x2,x4,x6,x7,x8}, among which x3 and x5 are true.

[0095] In the present invention, for different zombie Trojan data to be determined, according to the different event urgency attribute functions f5(x) calculated in step A3, corresponding multi-granularity zombie Trojan information granularization models are constructed in descending order of urgency levels.

[0096] D: Zombie Trojan Information Granularization Model (BDM) from multiple granularity levels k In the process, the optimal zombie Trojan judgment granularity is selected based on the coordination of decision attributes;

[0097] When constructing a multi-level granularity model for bot information, on the one hand, if the time granularity T is too fine, some key data will be filtered out, resulting in a lack of effective support for determining the authenticity of bot incidents and reduced accuracy. On the other hand, if the time granularity T is too coarse, the amount of bot data to be determined will increase, data export will be time-consuming, and manual verification costs will be high. Therefore, it is necessary to select the most appropriate time granularity from the multiple granularity levels to ensure efficient and accurate verification of bot incidents.

[0098] In the present invention, when judging based on the coordination of decision attributes, the multi-granularity level zombie Trojan information granular model 1≤k≤I, if Then the zombie Trojan information granulation model is called coordinated, otherwise it is called inconsistent. d is the decision attribute set of real zombie Trojan data, R T is the decision attribute set of the zombie Trojan data to be determined;

[0099] In this embodiment, according to the result analysis in step C3, since The first layer of zombie Trojan information granularity model is coordinated. Using this layer of granularity has the advantage of high accuracy, but still has the disadvantage of high judgment cost; The second layer of zombie Trojan information granularity model It is coordinated. Using this layer of granularity basically meets the judgment requirements, and the labor cost and time cost are better than the first layer of granularity model; The third layer of zombie Trojan information granularity model It is inconsistent. The granularity of the judgment model at this level is too large and can no longer meet the judgment requirements. Therefore, the granularity division method at this level is not considered for the time being.

[0100] Therefore, in this type of zombie Trojan information granularity model In the example, the time granularity T in seconds is the optimal time granularity choice.

[0101] E: Select the corresponding level of zombie Trojan information granularity model based on the optimal zombie Trojan judgment granularity obtained in step D, and then determine the authenticity of the corresponding zombie Trojan data by querying the log information of the host corresponding to the controlled IP in the destination IP attribute function f3(x);

[0102] When determining the authenticity of the zombie Trojan data to be determined, if the attribute factors of the zombie Trojan data to be determined meet any one of the following conditions, then the zombie Trojan data to be determined is determined to be authentic zombie Trojan data; otherwise, it is not authentic zombie Trojan data;

[0103] Condition 1: The time attribute function f1(x) of the zombie Trojan data to be determined, that is, the suspected controlled time of the zombie Trojan data to be determined is within the set time range; where the time range is (t x -t b , t x +t b ), t x represents the controlled time of the real zombie Trojan data that is closest to the suspected controlled time f1(x) of the zombie Trojan data to be determined and has the same controlled end IP address, t b is the set time threshold. In this embodiment, t b The value is 10 minutes;

[0104] In the present invention, if the time attribute function f1(x) of the zombie Trojan data to be determined is within the set time range, it proves that there is a controlled event of a real zombie Trojan with the same controlled end IP within the same time range, and the zombie Trojan data to be determined can be determined to be a real zombie Trojan with a high probability;

[0105] Condition 2: The IP correlation attribute function f6(x) of the zombie Trojan data to be determined, that is, the IP address matching rate R between the real zombie Trojan data in the zombie Trojan real data set and the zombie Trojan data to be determined is greater than or equal to the set matching threshold R b In this embodiment, R b The value is 0;

[0106] In the present invention, if the IP correlation attribute function f6(x) of the zombie Trojan data to be determined is greater than or equal to the matching threshold R b If the value is 0, it means that the difference between the integer representation IP1 of the control end IP address of the real zombie Trojan data and the integer representation IP2 of the control end IP address of the zombie Trojan data to be determined is within the set IP address deviation range threshold. The control end IP addresses of the real zombie Trojan data and the zombie Trojan data to be determined are similar, and there is a high probability that they form a local area network. Therefore, the zombie Trojan data to be determined is likely to be a real zombie Trojan.

[0107] F: Put the undetermined zombie Trojan data that has been determined to be real zombie Trojan data in step E into the zombie Trojan real data set, and update the zombie Trojan real data set.

Claims

1. A method for determining the authenticity of zombie Trojans on the Internet, characterized in that: The following steps are included in sequence: A: Obtain a dataset of zombie Trojans to be determined and determine the zombie Trojan attribute factors of the zombie Trojan data to be determined; Among them, the zombie Trojan attribute factors include time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), unit attribute function f4(x), event urgency attribute function f5(x) and IP correlation attribute function f6(x); time attribute function f1(x) includes the suspected controlled time of the zombie Trojan data to be determined, source IP attribute function f2(x) includes the control end IP and the control end port; destination IP attribute function f3(x) includes the controlled end IP and the controlled end port; unit attribute function f4(x) includes the controlled IP affiliation and the destination IP affiliation; event urgency attribute function f5(x) is the different urgency levels set in descending order according to the reporting time of the zombie Trojan data to be determined; IP correlation attribute function f6(x) is the matching rate between the real zombie Trojan data and the control end IP address of the zombie Trojan data to be determined; B: Using the multiple zombie attribute factors obtained in step A, based on granular computing theory, a single-granularity zombie information granular model BDM = (U, C∪{d}) is constructed. Where U represents the object, C represents the conditional attribute, and d represents the decision attribute. C: Using the time attribute function f1(x) obtained in step A and the single-granularity level zombie Trojan information granulation model BDM constructed in step B, based on the multi-granularity rough set theory, the domain U is divided by the attribute method, and according to the event urgency f5(x) of the zombie Trojan data to be determined, the multi-granularity level zombie Trojan information granulation model BDM is constructed in sequence. k =(U,T k ,C∪{d}); where the domain U is the object U, T represents the time granularity, k represents the number of layers of the granularity model, C represents the conditional attribute, and d represents the decision attribute; D: Zombie Trojan Information Granularization Model (BDM) from multiple granularity levels k In the process, the optimal zombie Trojan judgment granularity is selected based on the coordination of decision attributes; E: Select the corresponding level of zombie Trojan information granularity model based on the optimal zombie Trojan judgment granularity obtained in step D, and then determine the authenticity of the corresponding zombie Trojan data by querying the log information of the host corresponding to the controlled IP in the destination IP attribute function f3(x); In step D, when judging based on the coordination of decision attributes, the multi-granularity level zombie Trojan information granular model BDM k =(U,T k ,C∪{d}), 1≤k≤I, if Then the zombie Trojan information granulation model is called coordinated, otherwise it is called inconsistent; Among them, R d is the decision attribute set of real zombie Trojan data, R T It is the decision attribute set of the zombie Trojan data to be determined.

2. The method for determining the authenticity of a zombie Trojan on the Internet according to claim 1, characterized in that: Described step A comprises the following steps: A1: Obtain a dataset of zombie Trojans to be identified; A2: Using the zombie Trojan data set to be determined, obtain the time attribute function f1(x), source IP attribute function f2(x), destination IP attribute function f3(x), and unit attribute function f4(x) of the zombie Trojan data to be determined; A3: Using the unidentified zombie Trojan data set, the event urgency attribute function f5(x) of the corresponding unidentified zombie Trojan data is set to different urgency levels in descending order according to the reporting time of the unidentified zombie Trojan data. The time priority processing order is descending. A4: Construct a real zombie Trojan data set, and calculate the matching rate of the control end IP address for the real zombie Trojan data in the real zombie Trojan data set and the zombie Trojan data to be determined in the zombie Trojan data set. The IP address matching rate is obtained as the IP correlation attribute function f6(x) of the zombie Trojan data to be determined.

3. The method for determining the authenticity of zombie Trojans on the Internet according to claim 2, characterized in that: The calculation method of the IP address matching rate in step A4 is as follows: A41: Construct a real zombie Trojan data set consisting of real zombie Trojan data; A42: Convert the IP addresses of the control end of the real zombie Trojan data in the real zombie Trojan data set into integers in sequence, and finally obtain the integer representation IP1 of the IP address of the control end of the real zombie Trojan data; A43: According to the method of step A42, obtain the integer representation IP2 of the control terminal IP address of the zombie Trojan data to be determined in the zombie Trojan data set to be determined; A44: Calculate the IP address matching ratio of the control end IP addresses of the real zombie Trojan data, represented by the integer type IP1, and the control end IP address of the zombie Trojan data to be determined, represented by the integer type IP2, to obtain the corresponding IP address matching ratio R. Among them, IP0 is the set IP address deviation range threshold.

4. The method for determining the authenticity of a zombie Trojan on the Internet according to claim 1, wherein: In the step C, based on the single-granularity level zombie Trojan information granular model BDM = (U, C ∪ {d}), let the total granularity level of the construction be I, and construct it layer by layer from fine to coarse, and the attribute set of each layer is recorded as The specific steps include: C1: Based on the single-granularity level zombie Trojan information granular model BDM = (U, C∪{d}), let the time granularity T be in seconds to obtain the first-level zombie Trojan information granular model BDM 1 =(U,T 1 ,C∪{d}); C2: Based on the single-granularity level zombie Trojan information granular model BDM = (U, C∪{d}), when the time granularity T is taken in minutes, the second-level zombie Trojan information granular model BDM is obtained. 2 =(U,T 2 ,C∪{d}); C3: Based on the single-granularity level zombie Trojan information granular model BDM = (U, C∪{d}), when the time granularity T is taken as the unit of time, the third-level zombie Trojan information granular model BDM is obtained 3 =(U,T 3 ,C∪{d}); Finally, we obtain three different levels of granularity of zombie Trojan information granularity models BDM 1 , BDM 2 and BDM 3 , and obtain the decision attribute set of different zombie Trojan data to be determined at the corresponding granularity level 5. The method for determining the authenticity of zombie Trojans on the Internet according to claim 1, characterized in that: In the above step E, when determining the authenticity of the zombie Trojan data to be determined, if the attribute factor of the zombie Trojan data to be determined meets any one of the following conditions, then the zombie Trojan data to be determined is determined to be authentic zombie Trojan data; otherwise, it is not authentic zombie Trojan data; Condition 1: The time attribute function f1(x) of the zombie Trojan data to be determined, that is, the suspected controlled time of the zombie Trojan data to be determined is within the set time range; where the time range is (t x -t b , t x +t b ), t x represents the controlled time of the real zombie Trojan data that is closest to the suspected controlled time f1(x) of the zombie Trojan data to be determined and has the same controlled end IP address, t b is the set time threshold; Condition 2: The IP correlation attribute function f6(x) of the zombie Trojan data to be determined, that is, the IP address matching rate R between the real zombie Trojan data in the zombie Trojan real data set and the zombie Trojan data to be determined is greater than or equal to the set matching threshold R b .

6. The method for determining the authenticity of zombie Trojans on the Internet according to claim 1, characterized in that: Also comprising step F; F: Put the undetermined zombie Trojan data that has been determined to be real zombie Trojan data in step E into the zombie Trojan real data set, and update the zombie Trojan real data set.

7. The method for determining the authenticity of a zombie Trojan on the Internet according to claim 3, wherein: In step A42, each segment of the control end IP address of the real zombie Trojan data is treated as an integer from 0 to 255, and then each segment of the control end IP address that has been converted into an integer is converted into binary form to obtain a corresponding binary number, and finally the obtained binary number is converted into a long integer, and finally the integer representation IP1 of the control end IP address of the real zombie Trojan data is obtained.

8. The method for determining the authenticity of zombie Trojans on the Internet according to claim 1, characterized in that: For multi-level granularity zombie Trojan information granular model BDM k =(U,T k ,C∪{d}), the time granularity T in seconds is selected as the optimal time granularity.

9. The method for determining the authenticity of zombie Trojans on the Internet according to claim 5, characterized in that: The time threshold is 10 minutes; the matching threshold R b The value is 0.

Citation Information

Patent Citations

  • Methods, devices, and storage media for proactively detecting IoT botnet Trojans

    CN110798439B

  • Cloud storage fine grit access control method and data uploading and data accessing method

    CN108900483A

  • DYNAMIC AND INTERACTIVE CONTROL METHOD OF A RESIDENTIAL GATEWAY CONNECTED TO A COMMUNICATION NETWORK, CORRESPONDING DEVICE AND COMPUTER PROGRAM

    FR3058015A1