首页|基于图重构和子图挖掘的僵尸网络检测方法

基于图重构和子图挖掘的僵尸网络检测方法

扫码查看
针对伪装后僵尸网络主机难以检测的问题,提出一种基于图重构和子图挖掘的僵尸网络检测方法(GR-SGM)。首先,将网络数据转化为图数据,并对其进行重构以此增强主机节点特征表示;其次,基于重构图中拓扑结构、节点的特征和位置变化设计僵尸网络子图评分函数,以此捕捉伪装后的特征,提取出僵尸网络子图,并对原始图和重构图进行预检测,以提高检测的准确率和效率,减少重构误差;最后,对预检测结果和僵尸网络子图进行综合评分,以获取完整的僵尸网络信息。在ISCX2014僵尸网络数据集和CICIDS2017僵尸网络数据集上的实验结果表明:GR-SGM的检测准确率分别达到99。98%和99。91%,F1分别达到99。94%和99。65%,相较于其他僵尸网络检测模型,GR-SGM能更加高效准确地识别僵尸网络节点,同时具有更低的误报率。
Botnet Detection Method Based on Graph Reconstruction and Subgraph Mining
Aiming at the problem that disguised botnet hosts are difficult to detect,a botnet detection method based on graph reconstruction and subgraph mining (GR-SGM) was proposed. Firstly,network data was converted into graph data which was reconstructed to enhance the host node feature representation. Then,based on the topological structure,node characteristics,and position changes in the reconstructed graph,a botnet subgraph scoring function was designed. In this way,the camouflaged features were captured,the botnet subgraph was extracted,and the original and reconstructed graphs were pre-detected to improve detection accuracy and efficiency reducing recon-struction errors. Finally,the pre-detection results and botnet subgraphs were comprehensively scored to obtain com-plete botnet information. Experimental results on the ISCX2014 botnet dataset and CICIDS2017 botnet dataset showed that the detection accuracy of GR-SGM was 99.98% and 99.91%,respectively,and the F1 reached 99.94% and 99.65%,respectively. Compared with other botnet detection models,GR-SGM could identify botnet nodes more efficiently and accurately,while having a lower false alarm rate.

botnetsubgraph mininggraph reconstructioncybersecuritypre-detection

景永俊、吴悔、陈旭、宋吉飞

展开 >

合肥工业大学计算机与信息学院,安徽 合肥 230601

北方民族大学 计算机科学与工程学院,宁夏 银川 750021

国家(中卫)新型互联网交换中心,宁夏中卫 755000

僵尸网络 子图挖掘 图重构 网络安全 预检测

2025

郑州大学学报(工学版)
郑州大学

郑州大学学报(工学版)

北大核心
影响因子:0.442
ISSN:1671-6833
年,卷(期):2025.46(1)