Classification-based suppression and blocking methods and systems for botnets with different communication architectures

By extracting communication parameters and performing pattern analysis of botnets, and combining protocol characteristics and network structure, precise blocking of botnets was achieved. This solved the problems of policy mismatch and insufficient defense in existing botnet defense strategies, and improved the effectiveness of cyberspace governance.

CN120979816BActive Publication Date: 2026-05-05CHINA INFORMATION TECH SECURITY EVALUATION CENT +1
2 Cites 0 Cited by

Patent Information

Application Number
CN202511400198.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2026-05-05
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

Existing defense technologies are insufficient to effectively deal with the diverse communication architectures of botnets, leading to policy mismatches, inadequate or excessive defenses, inability to achieve cross-domain collaboration, and inability to cope with cross-regional attacks.

Method used

By extracting communication parameters of botnets through traffic mirroring and protocol decoding, and analyzing control commands, heartbeat mechanisms and data synchronization characteristics in a patterned manner, combined with protocol characteristics and network structure, the suppression channels are identified, and differentiated blocking schemes are matched to adjust the blocking intensity and coordinate multi-point linkage operations.

Benefits of technology

It enables precise location and disconnection of botnets, reduces the impact on normal applications, dynamically responds to the evolution of botnets, avoids defense failure, and improves cyberspace governance capabilities.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention provides a method and system for classifying and suppressing zombie networks facing different communication architectures, which relates to the field of network security technology. The method includes: determining an implementable suppression channel according to control instructions, heartbeat mechanisms, and data synchronization characteristics, in combination with the protocol characteristics and network structure to which they belong; matching a corresponding blocking scheme based on the suppression channel; the blocking scheme is selected according to the communication architecture type of the zombie network, and the communication architecture type includes centralized control C2 communication type, peer-to-peer P2P communication type, and hybrid type; implementing blocking measures matching the blocking scheme through policy scheduling, adjusting the suppression blocking intensity according to network feedback, coordinating multi-point linkage operations, and evaluating the blocking effect at the same time. The present invention enhances the ability to govern zombie networks in cyberspace by effectively cutting off and interfering with the communication links of centralized control communication type, peer-to-peer communication type, and hybrid type zombie networks.
Need to check novelty before this filing date? Find Prior Art