恶意挖矿流量快速检测框架的设计与实践

DESIGN AND PRACTICE OF MALICIOUS MINING TRAFFIC RAPID DETECTION FRAMEWORK

  • 摘要: 随着互联网的发展,恶意软件的数量越来越多,其中恶意挖矿软件利用系统漏洞劫持用户设备进行数字货币的挖掘,隐蔽地消耗着用户设备的计算资源和网络资源,是许多单位关注的重点问题之一。针对当前恶意挖矿行为难以检测,准确率低等问题,设计一种新型的快速恶意挖矿流量检测框架。该框架采用清晰的流程组合实现了可扩展的处理能力,通过针对性提取挖矿流量特征和优化的朴素贝叶斯算法实现准确的检测能力,借助灵活的模块配置实现了高兼容性的部署能力。最终分析并配置了校园网络应用环境,并通过实验证明该框架能够有效地对加密、非加密和基于 IPv6 传输的挖矿流量实现快速检测。

     

    Abstract: With the development of the Internet, the number of malware is getting more and more, among which the malicious mining software uses the system vulnerabilities for digital currency mining, and secretly consumes the computing resources and network resources of the system, which is one of the priorities of many groups. Aiming at the problems of current malicious mining behavior being difficult to detect and low in accuracy, this paper designs a new fast malicious mining traffic detection framework. The framework achieved scalable processing capabilities through clear process combinations, accurate detection capabilities through targeted extraction of mining traffic characteristics and optimized naive Bayesian algorithms, and highly compatible deployment capabilities through flexible module configuration. This paper analyzed and configured the campus network application environment, and proved through experiments that the framework could effectively detect encrypted, non-encrypted and IPv6-based mining traffic quickly.

     

/

返回文章
返回