Patent
Botnet detection method and controller
Tao Jing,Li Jianfeng,Cai Qishen +2 more
- 25 Nov 2015
5
TL;DR: In this article, a botnet detection method and a controller is presented, which comprises steps: statistical information of each stream forwarding rule reported by an openflow switch in an SDN is received, wherein the statistical information comprises first matching times of a sub-stream forwarding rule and second matching time of a mother stream forwarding rules, an access probability set for each server to which any user terminal is accessed is determined, and similarities of user terminals accessed to any two servers are calculated by pairwise, and an access similarity matrix is obtained; and spectral clustering algorithm is adopted to carry
read more
Abstract: The embodiment of the invention provides a Botnet detection method and a controller. The method comprises steps: statistical information of each stream forwarding rule reported by an openflow switch in an SDN is received, wherein the statistical information comprises first matching times of a sub stream forwarding rule and second matching times of a mother stream forwarding rule; according to the first matching times and the second matching times, an access probability set for each server to which any user terminal is accessed is determined; according to the access probability set, similarities of user terminals accessed to any two servers are calculated by pairwise, and an access similarity matrix is obtained; and spectral clustering algorithm is adopted to carry out spectral clustering on the access similarity matrix and according to a clustering result, whether a Botnet exists or not can be determined. A source IP address in the mother stream forwarding rule is a subnet address, the processing load of the controller can be greatly reduced, and the Botnet is determined based on access similarities, and the Botnet detection efficiency can be improved.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Classification method and electronic equipment
Yang Fangxun
- 27 Jul 2016
TL;DR: In this paper, a traffic classification method based on spectral clustering is proposed, which can solve a technical problem of a complicated traffic classification in the prior art, and the method provided by the invention can solve the traffic classification problem.
3
Patent
Botnet detection system and method in software-defined network
Chen Jing,Du Ruiying,Kun He +2 more
- 08 May 2018
TL;DR: In this paper, a botnet detection system and method in a software-defined network is described, which comprises a data preheating module, a topology collection module, flow graph extraction module and a detection engine module.
3
Patent
Botnet detection system and method thereof
Sun Minggong,Huang Qiongying,Zhang Zongquan +2 more
- 10 Nov 2017
TL;DR: In this paper, the authors proposed a botnet detection method using network record files of computer equipment, filtering the network record file according to an equipment startup time state record of the computer equipment and a network white list.
1
Patent
Method, device, and system for transmitting message
Chen Huadong
- 04 Jan 2019
TL;DR: In this article, an SDN forwarding device determines whether the target server is a server in the same network, and then sends the uplink GTPU message to a target gateway, the target gateway being a gateway corresponding to the target servers.
Patent
Packet transmission method, apparatus, and system
Chen Huadong
- 21 Mar 2019
TL;DR: In this article, a packet transmission method, an apparatus, and a system are provided, to improve packet transmission efficiency, where the uplink GTPU packet carries an IP address of a target server; the SDN forwarding apparatus determines whether the target server is an intranet server.
References
Patent
Method and apparatus for detecting compromised host computers
David A. Hoeflin,Anestis Karasaridis,Carl Brian Rexroad +2 more
- 29 Sep 2006
TL;DR: In this article, a method and apparatus for detecting compromised host computers (e.g., Bots) are disclosed, where the method identifies a plurality of suspicious hosts and analyzes network traffic of the plurality suspicious hosts to identify a plurality suspicious hub-servers.
240
Patent
Behavior-detection-based network traffic identification method and device
Wan Miao
- 02 Apr 2014
TL;DR: In this paper, a behavior-detection-based network traffic identification method and a behavior detection-based traffic identification device are presented, which comprises the following steps of capturing data packet information of network traffic, and performing TCP (transmission control protocol) session recombination to extract information of each TCP session stream respectively.
8
Patent
Method of detecting worm activity based on flux information
Xiaorui Gong,Yu Chen,Lixiong Zheng,Aihua Piao +3 more
- 21 May 2008
7
Patent
Botnet detection method and device
Zeng Bin,Su Xin,Zhang Dafang,Wu Dazhi +3 more
- 18 Dec 2013
TL;DR: In this paper, a botnet detection method and device is presented, which includes: according to at least one first attribute information for representing traffic data attributes, classifying global traffic data acquired within preset duration to obtain at least 1 service traffic data cluster, performing classification and division operation processing on the service traffic dataset according to index parameters corresponding to the service data data cluster; according to a result of operation processing of each service traffic datasets, determining service traffic clusters generated in the communication process of the botnet.
6
Patent
Peer-to-peer botnet core node detection method and detection device
Xu Xiaolong,Zhang Yun,Xu Lei,Xu Jia,Li Qianmu,Sun Yanfei +5 more
- 23 Apr 2014
TL;DR: In this article, a peer-to-peer botnet core node detection method is proposed, which aims at the deficiency of the traditional P2P botnet detection method by carrying out characteristic extraction and analysis on a network conversation and abstracting an analysis result into an undirected graph.
5
Related Papers (5)
Chen Jing,Du Ruiying,Kun He +2 more
- 08 May 2018
Liu Jia Nan,Song Bing,Li Baisong +2 more
- 09 Jul 2014
Zhang Dafang,Guo Li,Li Yanbiao +2 more
- 06 Apr 2018