Botnet identification method, apparatus and device, and storage medium

By obtaining the specified attribute values ​​of the data packet, calculating the total hit points and using random forests to identify the botnet, the problem of botnet recognition in the prior art is solved, and an accurate and interpretable recognition effect is achieved.

CN120238328APending Publication Date: 2025-07-01BEIJING BANGCLE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311865039.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

It is difficult to effectively identify botnets in the prior art, resulting in the inability to prevent their malicious operations in a timely manner.

Method used

By obtaining the attribute values ​​of the specified attributes of the data packet transmitted by the target network, using the attribute value list to calculate the total hit points, select the target specified attributes, and enter a random forest that integrates multiple types of decision trees to identify whether the target network is a botnet.

Benefits of technology

It provides an effective botnet recognition method, improves the accuracy and interpretability of the recognition, reduces the risk of overfitting, and enhances the robustness of the recognition results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238328A_ABST
    Figure CN120238328A_ABST
Patent Text Reader

Abstract

The invention discloses a botnet identification method and device, electronic equipment and a computer readable storage medium, and aims to solve the problem of how to effectively identify a botnet in the prior art. The method comprises the following steps: acquiring attribute values of specified attributes of a plurality of data packets transmitted by a target network; the specified attribute of the data packet can represent whether the transmission of the data packet is triggered by a controller of the botnet; for each specified attribute, based on an attribute value list and the single hit integral corresponding to each attribute value in the list, determining a total hit integral of the specified attribute obtained by the attribute value of the specified attribute of the plurality of data packets due to hitting the list; selecting a specified attribute from the specified attributes as a target specified attribute according to the total hit integral; and inputting the attribute value of the target specified attribute into the random forest integrated with the multi-type decision tree so as to trigger the random forest to output an identification result aiming at whether the target network is the botnet or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technologies, and in particular, to a method, device, electronic device, and computer-readable storage medium for identifying a botnet. Background Art

[0002] A botnet is a maliciously infected network that also infects other systems or devices connected in the same network.

[0003] The formation principle of a botnet is that an attacker (bot-herder) uses one or more propagation means to infect a large number of computing devices with a bot program virus, thereby forming a network that can be controlled one-to-many between the attacker and the infected computing devices.

[0004] For a computing device infected with a bot program virus, the attacker - who can also be referred to as the controller of the botnet at this time - will host it on a server called a CC server and send commands from the CC server to the infected computing device to control the infected computing device to perform malicious operations without its knowledge, such as sending spam emails, conducting a Distributed Denial of Service (DDos) attack, etc. Therefore, the identification of botnets is of great significance.

[0005] How to effectively identify a botnet is an issue that the existing technology urgently needs to solve. Summary of the Invention

[0006] Embodiments of the present application provide a method for identifying a botnet to solve the problem of how to effectively identify a botnet in the existing technology.

[0007] Embodiments of the present application also provide an apparatus, an electronic device, and a computer-readable storage medium for identifying a botnet.

[0008] Embodiments of the present application adopt the following technical solutions:

[0009] A method for identifying a botnet includes:

[0010] Obtaining the attribute values of specified attributes of several data packets transmitted by a target network; the specified attribute of the data packet is an attribute that can characterize whether the transmission of the data packet is triggered by the controller of the botnet;

[0011] For each of the specified attributes, perform the following respectively: Based on the attribute value list and the single hit scores corresponding to each attribute value in the attribute value list, determine the total hit score of the specified attribute of the several data packets obtained due to hitting the attribute value list; wherein, in the attribute value list, the specified attributes of the data packets transmitted by the botnet and the corresponding attribute values are stored.

[0012] Select at least one specified attribute from each of the specified attributes as the target specified attribute according to the total hit score of each of the specified attributes.

[0013] Input the attribute values of the target specified attribute of the several data packets into a random forest integrated with multiple types of decision trees to trigger the random forest to output an identification result as to whether the target network is a botnet.

[0014] An identification device for a botnet, comprising:

[0015] An attribute value acquisition unit, configured to acquire the attribute values of the specified attributes of several data packets transmitted by a target network; the specified attributes of the data packets are attributes that can characterize whether the transmission of the data packets is triggered by a controller of a botnet.

[0016] An integration unit, configured to perform the following respectively for each of the specified attributes: Based on the attribute value list and the single hit scores corresponding to each attribute value in the attribute value list, determine the total hit score of the specified attribute of the several data packets obtained due to hitting the attribute value list; wherein, in the attribute value list, the specified attributes of the data packets transmitted by the botnet and the corresponding attribute values are stored.

[0017] An attribute selection unit, configured to select at least one specified attribute from each of the specified attributes as the target specified attribute according to the total hit score of each of the specified attributes.

[0018] An identification unit, configured to input the attribute values of the target specified attribute of the several data packets into a random forest integrated with multiple types of decision trees to trigger the random forest to output an identification result as to whether the target network is a botnet.

[0019] An electronic device, comprising: a memory and a processor, wherein, the memory is configured to store a program; the processor is coupled to the memory and configured to execute the program stored in the memory to perform the above-mentioned botnet identification method.

[0020] A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer, can implement the above-mentioned botnet identification method.

[0021] The above at least one technical solution adopted in the embodiments of the present application can achieve the following beneficial effects:

[0022] By obtaining the attribute values of specified attributes of several data packets transmitted by the target network, determining the total hit score for each specified attribute, and selecting the target specified attribute based on the total hit score, and then inputting the attribute value of the target specified attribute into a random forest integrating multiple types of decision trees to identify whether the target network is a botnet, thereby providing an effective way to identify a botnet based on an attribute (i.e., the specified attribute) that can characterize whether the transmission of the data packet is triggered by the controller of the botnet, and solving the problem of how to effectively identify a botnet existing in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application, and do not constitute an improper limitation to the present application. In the drawings:

[0024] Figure 1 is a specific implementation flowchart of a method for identifying a botnet provided by an embodiment of the present application;

[0025] Figure 2 is a schematic diagram of the random forest marking labels for whether different traffic is botnet traffic;

[0026] Figure 3 is a specific structural schematic diagram of a device for identifying a botnet provided by an embodiment of the present application;

[0027] Figure 4 is a specific structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0029] As can be known to those of ordinary skill in the art, with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0030] In the description, claims and the above-mentioned drawings of this application, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of this application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0031] To solve the problem of how to effectively identify botnets in the prior art, an embodiment of this application provides a method for identifying botnets.

[0032] The execution subject of this method can be any computing device, such as a server, or it can also be software running on a computing device, specifically, for example, a botnet identification software. The embodiment of this application does not limit what kind of computing device or software the execution subject is.

[0033] In addition, different steps of this method can be implemented by different computing devices or software. The embodiment of this application does not limit which computing device or software is specifically used to implement which step.

[0034] For the convenience of description, the following takes the execution subject of this method as a botnet identification software as an example to describe this method provided by the embodiment of this application in detail.

[0035] Please refer to the attached Figure 1 figures, which is a specific implementation flowchart of a method for identifying botnets provided by the embodiment of this application, including the following steps:

[0036] Step 11: Obtain the attribute values of specified attributes of several data packets transmitted by the target network;

[0037] The target network mentioned here refers to the network to be identified whether it is a botnet. For example, it can be any network that may be infected with botnet viruses.

[0038] Regarding the specific type of the target network, if it is classified by the scope of the network, the type of the target network can be a wide area network, a metropolitan area network or a local area network; if it is classified by the users of the network, the type of the target network can be a public network or a private network; if it is classified by the networking method of the network, the type of the target network can be a cellular network, the Internet (including a conventional Internet, a satellite Internet) or the Internet of Things.

[0039] The embodiments of the present application do not limit the specific type of the target network. Any network type that may form a botnet can fall into the category of the target network type described in the embodiments of the present application.

[0040] The target network usually includes at least one computing device. The computing device can be any type of computing device, such as a user's personal computer, smartphone, smart wearable device, robot, or server, etc.

[0041] In the embodiments of the present application, the "data packets transmitted by the target network" may include the data packets transmitted between the computing devices in the target network, or may also include the data packets transmitted between the computing devices in the target network and other computing devices outside the target network.

[0042] In the embodiments of the present application, the specified attribute of the data packet is an attribute that can characterize whether the transmission of the data packet is triggered by the controller of the botnet.

[0043] In an alternative embodiment, the specified attributes of several data packets transmitted by the target network may include: the attribute values of the haplotype attributes of each data packet among the several data packets, and / or, the attribute values of the statistical attributes of the several data packets.

[0044] The haplotype attribute refers to an attribute possessed by a single data packet.

[0045] Exemplarily, the haplotype attribute may include, but is not limited to, one or more of the following:

[0046] The transmission protocol; the source IP address; the number of bytes carried by the data packet; the source port; the destination IP address; the destination port.

[0047] The statistical attribute refers to an attribute that may require statistical information of multiple data packets to be determined.

[0048] Exemplarily, the statistical attribute may include, but is not limited to, one or more of the following:

[0049] The time when the source computing device and the destination computing device first transmit a data packet;

[0050] The duration for which the source computing device and the destination computing device are connected together through the target network;

[0051] The total number of data packets sent and received during the connection duration between the source computing device and the destination computing device;

[0052] The net flow number from the source computing device;

[0053] The net flow number received by the destination computing device;

[0054] The directory of the transmission details.

[0055] The above-mentioned "net number of flows from the source computing device" refers to the total number of data packets sent by the source computing device of the data packet (the computing device corresponding to the source IP address of the data packet) as the sender; the "net number of flows received by the destination computing device" refers to the total number of data packets received by the destination computing device of the data packet (the computing device corresponding to the destination IP address of the data packet) as the receiver.

[0056] The above-mentioned "directory for transmission details" refers to a directory used to store the data that will be attached during the transmission of data packets. Among them, the data that will be attached during the transmission of data packets includes, for example, but is not limited to: the path of the file being transferred during the upload file process, the file type of the transferred content, etc.

[0057] When the specified attribute includes the haplotype attribute of each data packet, in an optional implementation manner, the specific implementation manner of step 11 may include: obtaining the attribute values of the haplotype attributes of each data packet among a plurality of data packets.

[0058] When the specified attribute includes the statistical attributes of a plurality of data packets, in an optional implementation manner, the specific implementation manner of step 11 may include: obtaining the attribute values of the statistical attributes of a plurality of data packets.

[0059] When the specified attribute includes the haplotype attribute of each data packet and the statistical attributes of a plurality of data packets, in an optional implementation manner, the specific implementation manner of step 11 may include: obtaining the attribute values of the haplotype attributes of each data packet among a plurality of data packets, and the attribute values of the statistical attributes of the plurality of data packets.

[0060] In an optional implementation manner, a packet capture tool may be used to capture the data packets transmitted by the target network, and then the attribute values of the specified attribute may be obtained based on the data packets; a security monitoring device may also be used to collect network traffic data, so as to obtain the attribute values of the specified attribute. The embodiments of the present application do not limit how to obtain the attribute values of the specified attributes of a plurality of data packets transmitted by the target network.

[0061] For the data packets captured by the packet capture tool and the data collected by the security monitoring device, preprocessing including data cleaning, removing redundant information, standardization, etc. can be performed, and then based on the captured data packets / collected data, the attribute values of the specified attributes of a plurality of data packets transmitted by the target network can be obtained.

[0062] Step 12: For each specified attribute of a number of data packets transmitted by the target network, perform the following respectively: Based on the attribute value list and the single hit scores respectively corresponding to each attribute value in the attribute value list, determine the total hit score of the specified attribute of the number of data packets obtained by performing Step 11 due to hitting the attribute value list.

[0063] Among them, in the attribute value list, the specified attributes of the data packets transmitted by the botnet and the corresponding attribute values are saved. Thus, the attribute value list can be understood as a kind of blacklist of attribute values.

[0064] Taking a botnet identification software as the execution subject as an example, in an optional implementation, the software can receive the attributes (including but not limited to specified attributes) and the corresponding attribute values obtained from each identified botnet input by the technician, and store the received attributes and the corresponding attribute values into the attribute value list (or called the matching rule library). In this way, the attribute value list can be used as a kind of blacklist.

[0065] The attributes input by the technician can have one or more corresponding attribute values.

[0066] In addition, the software can also receive the single hit scores respectively input by the technician for each attribute value, and save the single hit scores in the way of corresponding storage with the attribute values.

[0067] The scores of the attribute values corresponding to the same attribute can be the same or different; the attribute values corresponding to different attributes can also be the same or different.

[0068] In an optional implementation, different attribute values can all correspond to the same single hit score, and this score can be, for example, 1.

[0069] In Step 12, based on the attribute value list, for each specified attribute, the specified operation can be looped until all the matches of the attribute values of the specified attribute and the determination of the single hit scores are completed, and then the sum of the single hit scores corresponding to all the attribute values of the specified attribute is calculated, that is, the total hit score of the specified attribute is calculated.

[0070] The specified operation specifically includes:

[0071] By matching the specified attribute and its attribute value with the attributes and attribute values in the attribute value list, determine whether the specified attribute and its attribute value hit any attributes and attribute values in the attribute value list;

[0072] If a hit occurs, the single - hit score corresponding to the attribute value in the list of attribute values of the hit can be further determined based on the stored single - hit score. For example, 1 point. If there is no hit, the specified attribute and its attribute value can be discarded.

[0073] In a specific example, assume that the specified attribute is the source IP address, and the corresponding attribute values are A, B, C, and D respectively. Then, for the four attribute values A, B, C, and D of the source IP address, the above - mentioned method is respectively used to match with the source IP address and its corresponding attribute values in the list of attribute values. If it is assumed that the attribute values A, B, and C hit the source IP address and its corresponding attribute values in the list of attribute values, while D does not hit, and further assume that the single - hit scores corresponding to the attribute values in the list of hit attribute values are all 1 point, then for the specified attribute of "source IP address", its total hit score can be statistically obtained as 3.

[0074] Step 13: Select at least one specified attribute from the respective specified attributes as the target specified attribute according to the total hit scores of the respective specified attributes of several data packets transmitted by the target network.

[0075] In an alternative implementation, for example, a specified attribute that meets the preset specified attribute value selection condition of the total hit score can be selected as the target specified attribute.

[0076] Exemplarily, assuming that the single - hit average scores are all positive numbers, a specified attribute with a total hit score higher than the preset score threshold can be selected as the target specified attribute.

[0077] In the embodiments of the present application, the attribute values of the target specified attribute can be used as the features for reference in identifying whether the target network is a botnet.

[0078] By using the method provided in the embodiments of the present application to visualize the feature extraction process as scores, the extracted features can be clearly corresponding to the specific matching rules (i.e., the attributes and attribute values in the matching rule library / attribute value list), improving the interpretability of the feature selection result.

[0079] In the embodiments of the present application, technicians are allowed to set the attributes and attribute values in the matching rule library / attribute value list according to the actual situation, which has the advantage of being able to flexibly meet different actual needs.

[0080] Step 14: Input the attribute values of the target specified attribute of several data packets into a random forest integrating multiple types of decision trees to trigger the random forest to output the recognition result for whether the target network is a botnet.

[0081] The above-mentioned random forest is used to take the attribute values of the data packets of a network (such as a target network) as input to identify whether the network transmitting the data packets with such attribute values is a botnet.

[0082] The random forest is a machine learning algorithm and a classifier that uses multiple decision trees to train samples and make integrated predictions. In the embodiments of the present application, based on the random forest, the attribute values of the target specified attributes input into the random forest can be used to construct multiple types of decision trees by using the random splitting technology of nodes, and finally the multiple types of decision trees are combined, and the final prediction result is obtained by voting - that is, the recognition result of whether the target network is a botnet.

[0083] The above-mentioned multiple types of decision trees refer to at least two types of decision trees.

[0084] Exemplarily, the multiple types of decision trees include:

[0085] Classification and Regression Tree (CART), Iterative Dichotomiser 3 (ID3), and a decision tree constructed based on the C4.5 algorithm. Among them:

[0086] ID3 is the earliest proposed decision tree (decision tree algorithm), and this decision tree uses information gain as the splitting criterion.

[0087] The C4.5 algorithm was proposed by J.Ross Quinlan on the basis of ID3. The decision tree constructed based on the C4.5 algorithm is an improved version of ID3 and still uses the information gain ratio as the splitting criterion.

[0088] CART can be used for classification and can also be used for regression problems. That is, CART can be used as both a classification tree and a regression tree. CART uses the Gini index as the splitting criterion.

[0089] As Figure 2 shown, it is a schematic diagram of the random forest marking labels for whether different traffic (the traffic here can be understood as several data packets) is botnet traffic based on the attribute values of the target specified attributes of the input different traffic.

[0090] In Figure 2 , the numbers in the first column from the left represent the traffic numbers; the numbers in the second column from the left to the second column from the right are the attribute values of different target specified attributes respectively; the content in the first row is the name of the target specified attribute; the content in the first column from the right is the label marked by the random forest for the traffic: TRUE indicates that the recognition result is botnet traffic, and FALSE indicates that the recognition result is non-botnet traffic.

[0091] For a target network, the random forest determines the label that appears the most frequently by counting the labels of the traffic for the target network, and then outputs the recognition result for the target network based on the label.

[0092] Exemplarily, assuming that the label that appears the most frequently is determined to be "TRUE", then the recognition result for the target network can be output as "TRUE" - indicating that the target network is recognized as a botnet.

[0093] In addition, the above-mentioned random forest can also output the mean decrease accuracy values corresponding to each target specified attribute.

[0094] The mean decrease accuracy value, that is, Mean Decrease Accuracy, is an index value used to measure the accuracy of the random forest on the original sample data that has not been shuffled and the shuffled original sample data.

[0095] Based on the mean decrease accuracy values corresponding to each target specified attribute, subsequently, among the target specified attributes, the target specified attributes with larger mean decrease accuracy values (such as greater than a preset mean decrease accuracy value threshold, or ranked among the top 5 in terms of mean decrease accuracy value) can be determined as relatively important target specified attributes, so that when performing botnet recognition subsequently, the attribute values of the relatively important target specified attributes can be preferentially selected as the basic data used when identifying whether the corresponding network is a botnet.

[0096] In the embodiments of the present application, the random forest combines multiple types of decision trees and comprehensively considers the results of each type of decision tree through voting, thereby reducing the overfitting risk of a single model and improving the robustness of the overall model;

[0097] At the same time, the random forest usually performs well when dealing with complex data sets and features, and can capture the differences between different decision trees, thus ensuring the generalization ability of the process described in step 14;

[0098] In addition, the random forest can improve the evaluation of the importance of each feature (target specified attribute) for obtaining the recognition result, help determine the key features (i.e., the aforementioned relatively important target specified attributes) affecting the behavior of the botnet, and contribute to better understanding and interpreting the classification / recognition result of the target network.

[0099] By using the method provided in the embodiments of the present application, by obtaining the attribute values of the specified attributes of several data packets transmitted by the target network, determining the total hit score for each specified attribute, and selecting the target specified attribute based on the total hit score, and then inputting the attribute value of the target specified attribute into a random forest integrating multiple types of decision trees to identify whether the target network is a botnet, thus providing an effective way to identify a botnet based on the attributes (i.e., specified attributes) that can characterize whether the transmission of data packets is triggered by the controller of the botnet, and solving the problem of how to effectively identify a botnet existing in the prior art.

[0100] In an alternative embodiment, to minimize the attack of the target network on other computing devices after identifying that the target network is a botnet, the method provided in the embodiments of the present application may further include: starting the processing measures preset for the botnet.

[0101] Exemplarily, starting the processing measures preset for the botnet may include, but is not limited to, at least one of the following:

[0102] Sending an alarm message for prompting that the target network is a botnet;

[0103] Blocking the transmission of data packets with the IP address of the computing device in the target network as the source IP address;

[0104] Controlling the disconnection between the computing device already connected to the target network and the target network.

[0105] For the same inventive concept as the foregoing embodiments, to solve the problem of how to effectively identify a botnet existing in the prior art, the embodiments of the present application further provide an identification device for a botnet.

[0106] The specific structural schematic diagram of the device is as Figure 3 shown, and includes the following functional units:

[0107] An attribute value acquisition unit 31, configured to acquire the attribute values of the specified attributes of several data packets transmitted by the target network; the specified attribute of the data packet is an attribute that can characterize whether the transmission of the data packet is triggered by the controller of the botnet;

[0108] An integration unit 32, configured to perform, for each of the specified attributes, respectively: based on the attribute value list and the single hit scores respectively corresponding to the attribute values in the attribute value list, determine the total hit score of the specified attribute of the several data packets obtained due to hitting the attribute value list; wherein, in the attribute value list, the specified attributes and the corresponding attribute values of the data packets transmitted by the botnet are stored;

[0109] An attribute selection unit 33 is configured to select at least one specified attribute from each of the specified attributes as a target specified attribute according to the total hit score of each specified attribute.

[0110] An identification unit 34 is configured to input the attribute values of the target specified attributes of the several data packets into a random forest integrated with multiple types of decision trees, so as to trigger the random forest to output an identification result as to whether the target network is a botnet.

[0111] In an optional implementation manner, the attribute value acquisition unit 33 is specifically configured to:

[0112] acquire the attribute values of the haplotype attributes of each of the several data packets; and / or,

[0113] acquire the attribute values of the statistical attributes of the several data packets.

[0114] In an optional implementation manner, the device provided in the embodiments of the present application may further include:

[0115] A processing measure activation unit is configured to activate a pre-set processing measure for a botnet if the random forest outputs an identification result that the target network is a botnet.

[0116] Wherein, activating the pre-set processing measure for a botnet includes at least one of the following:

[0117] sending an alarm message for prompting that the target network is a botnet;

[0118] blocking the transmission of data packets with the IP address of the computing device in the target network as the source IP address;

[0119] controlling the disconnection between the computing device connected to the target network and the target network.

[0120] By using the above device provided in the embodiments of the present application, by acquiring the attribute values of the specified attributes of several data packets transmitted by a target network, determining the total hit score for each specified attribute, and selecting the target specified attribute based on the total hit score, and then inputting the attribute values of the target specified attribute into a random forest integrated with multiple types of decision trees to identify whether the target network is a botnet, an effective method for identifying a botnet based on an attribute (i.e., the specified attribute) that can characterize whether the transmission of a data packet is triggered by a controller of a botnet is provided, and the problem of how to effectively identify a botnet in the prior art is solved.

[0121] Due to the same inventive concept as the previous embodiments, the embodiments of the present application further provide an electronic device to solve the problem of how to effectively identify a botnet in the prior art.

[0122] As Figure 4 shown, the electronic device includes: a memory 41 and a processor 42. The memory 41 can be configured to store various other data to support operations on the electronic device. Examples of such data include instructions for any application or method for operating on the electronic device. The memory 41 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0123] The processor 42, coupled to the memory 41, is configured to execute the program stored in the memory 41 to perform the method for identifying a botnet described in the embodiments of the present application.

[0124] When the processor 42 executes the program in the memory 41, in addition to the above functions, other functions can also be implemented. For details, reference can be made to the descriptions of the previous embodiments.

[0125] Further, as Figure 4 shown, the electronic device further includes: a display 44, a communication component 43, a power supply component 45, an audio component 46 and other components. Figure 4 Only some components are schematically shown in Figure 4 the figure, which does not mean that the electronic device only includes

[0126] the components shown in the figure.

[0127] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solutions, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.

Claims

1. A method for identifying a botnet, characterized in that, including: obtaining the attribute values of specified attributes of a plurality of data packets transmitted by a target network; the specified attribute of the data packet is an attribute that can characterize whether the transmission of the data packet is triggered by the controller of the botnet; for each of the specified attributes, respectively execute: based on the attribute value list and the single hit scores corresponding to the respective attribute values in the attribute value list, determine the total hit score of the specified attribute of the plurality of data packets obtained due to hitting the attribute value list; wherein, in the attribute value list, the specified attributes of the data packets transmitted by the botnet and the corresponding attribute values are stored; select at least one specified attribute from each of the specified attributes as the target specified attribute according to the total hit scores of each of the specified attributes; input the attribute values of the target specified attribute of the plurality of data packets into a random forest integrating multiple types of decision trees to trigger the random forest to output an identification result as to whether the target network is a botnet.

2. The method according to claim 1, wherein Obtaining the attribute values of the specified attributes of a plurality of data packets transmitted by the target network includes: obtaining the attribute values of the haplotype attributes of each of the plurality of data packets; and / or, obtaining the attribute values of the statistical attributes of the plurality of data packets.

3. The method according to claim 2, wherein: the haplotype attribute includes at least one of the following: transmission protocol; source IP address; number of bytes carried by the data packet; source port; destination IP address; destination port; and / or, the statistical attribute includes at least one of the following: the time when the first data packet is transmitted between the source computing device and the destination computing device; the duration during which the source computing device and the destination computing device are connected together through the target network; the total number of data packets sent and received during the connection duration between the source computing device and the destination computing device; the net flow number from the source computing device; the net flow number received by the destination computing device; the directory of transmission details.

4. The method according to claim 1, wherein The multiple types of decision trees include: classification and regression tree CART, iteration binary tree generation 3 ID3, and decision trees constructed based on the C4.5 algorithm.

5. The method according to claim 1, characterized in that, The method further includes: if the random forest outputs an identification result that the target network is a botnet, then initiate the processing measures preset for the botnet; initiating the processing measures preset for the botnet includes at least one of the following: sending an alarm message for prompting that the target network is a botnet; blocking the transmission of data packets with the IP address of the computing device in the target network as the source IP address; controlling the disconnection between the computing device already connected to the target network and the target network.

6. An identification device for a botnet, characterized in that including: an attribute value acquisition unit for acquiring the attribute values of specified attributes of a plurality of data packets transmitted by a target network; the specified attribute of the data packet is an attribute that can characterize whether the transmission of the data packet is triggered by the controller of the botnet; An integration unit, which is configured to perform, respectively for each of the specified attributes: based on an attribute value list and the single-hit scores respectively corresponding to the attribute values in the attribute value list, determine the total hit score of the specified attribute of the several data packets obtained due to hitting the attribute value list; wherein, in the attribute value list, the specified attributes and the corresponding attribute values of the data packets transmitted by the botnet are stored. An attribute selection unit, which is configured to select at least one specified attribute from each of the specified attributes as a target specified attribute according to the total hit score of each of the specified attributes. An identification unit, which is configured to input the attribute values of the target specified attribute of the several data packets into a random forest integrated with multiple types of decision trees to trigger the random forest to output an identification result as to whether the target network is a botnet.

7. The device according to claim 6, characterized in that, An attribute value acquisition unit, specifically configured to: acquire the attribute values of the haplotype attributes of each of the several data packets; and / or, acquire the attribute values of the statistical attributes of the several data packets.

8. The apparatus according to claim 7, wherein: The haplotype attribute includes at least one of the following: transmission protocol; source IP address; number of bytes carried by the data packet; source port; destination IP address; destination port; and / or, the statistical attribute includes at least one of the following: time of first transmission of a data packet between the source computing device and the destination computing device; duration during which the source computing device and the destination computing device are connected together through the target network; total number of data packets sent and received during the connection duration between the source computing device and the destination computing device; number of net flows from the source computing device; number of net flows received by the destination computing device; directory of transmission details.

9. An electronic device, characterized in that, including: a memory and a processor, wherein, the memory is configured to store a program; the processor is coupled to the memory and is configured to execute the program stored in the memory to perform the method for identifying a botnet according to any one of claims 1 to 5.

10. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a computer, it can implement the method for identifying a botnet according to any one of claims 1 to 5.