首页> 外文会议>36th Annual IEEE International Computer Software and Applications Conference.;vol. 1.;Main Conference >Real-Time Fast-Flux Identification via Localized Spatial Geolocation Detection
【24h】

Real-Time Fast-Flux Identification via Localized Spatial Geolocation Detection

机译:通过局部空间地理位置检测进行实时快速通量识别

获取原文
获取原文并翻译 | 示例

摘要

Fast-flux service networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations between IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone.
机译:僵尸网络广泛使用的快速通行服务网络(FFSN)是一种通过快速活动进行恶意行为的规避技术。在性能较差的情况下,FFSN检测很容易失败,并且由于FFSN与内容分发网络(CDN)的相似性(负载平衡的正常行为)而导致误报率很高。在这项研究中,我们提出了一种用于实时识别FFSN的局部空间地理位置检测(LSGD)系统。我们认为,LSGD的网格分布具有精确的空间定位功能,可以分析IP地址分辨率之间的空间关系。此外,自治系统编号(ASN)用于增强本地化的地理特征。拟议的系统结合了LSGD,ASN和域名系统(DNS),可以很好地响应以识别潜在的FFSN。我们的实验结果表明,所提出的LSGD系统比最新的空间或时间检测方法具有更好的检测能力,与仅基于空间快照的方法相比,实时检测中的误报率更低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号