发明授权
US08307459B2 Botnet early detection using hybrid hidden markov model algorithm
有权
僵尸网络早期检测使用混合隐马尔可夫模型算法
- 专利标题: Botnet early detection using hybrid hidden markov model algorithm
- 专利标题(中): 僵尸网络早期检测使用混合隐马尔可夫模型算法
-
申请号: US12726272申请日: 2010-03-17
-
公开(公告)号: US08307459B2公开(公告)日: 2012-11-06
- 发明人: Hahn-Ming Lee , Ching-Hao Mao , Yu-Jie Chen , Yi-Hsun Wang , Jerome Yeh , Tsu-Han Chen
- 申请人: Hahn-Ming Lee , Ching-Hao Mao , Yu-Jie Chen , Yi-Hsun Wang , Jerome Yeh , Tsu-Han Chen
- 申请人地址: TW Taipei
- 专利权人: National Taiwan University of Science and Technology
- 当前专利权人: National Taiwan University of Science and Technology
- 当前专利权人地址: TW Taipei
- 优先权: TW98122517A 20090703
- 主分类号: G06F7/04
- IPC分类号: G06F7/04 ; G06F11/00
摘要:
A botnet detection system is provided. A bursty feature extractor receives an Internet Relay Chat (IRC) packet value from a detection object network, and determines a bursty feature accordingly. A Hybrid Hidden Markov Model (HHMM) parameter estimator determines probability parameters for a Hybrid Hidden Markov Model according to the bursty feature. A traffic profile generator establishes a probability sequential model for the Hybrid Hidden Markov Model according to the probability parameters and pre-defined network traffic categories. A dubious state detector determines a traffic state corresponding to a network relaying the IRC packet in response to reception of a new IRC packet, determines whether the IRC packet flow of the object network is dubious by applying the bursty feature to the probability sequential model for the Hybrid Hidden Markov Model, and generates a warning signal when the IRC packet flow is regarded as having a dubious traffic state.
公开/授权文献
信息查询