僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾...僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾邮件发送等攻击目的。该文提出一种与僵尸网络结构和C&C协议无关,不需要分析数据包的特征负载的僵尸网络检测方法。该方法首先使用预过滤规则对捕获的流量进行过滤,去掉与僵尸网络无关的流量;其次对过滤后的流量属性进行统计;接着使用基于X-means聚类的两步聚类算法对C&C信道的流量属性进行分析与聚类,从而达到对僵尸网络检测的目的。实验证明,该方法高效准确地把僵尸网络流量与其他正常网络流量区分,达到从实际网络中检测僵尸网络的要求,并且具有较低的误判率。展开更多
The hypersonic interception in near space is a great challenge because of the target’s unpredictable trajectory, which demands the interceptors of trajectory cluster coverage of the predicted area and optimal traject...The hypersonic interception in near space is a great challenge because of the target’s unpredictable trajectory, which demands the interceptors of trajectory cluster coverage of the predicted area and optimal trajectory modification capability aiming at the consistently updating predicted impact point(PIP) in the midcourse phase. A novel midcourse optimal trajectory cluster generation and trajectory modification algorithm is proposed based on the neighboring optimal control theory. Firstly, the midcourse trajectory optimization problem is introduced; the necessary conditions for the optimal control and the transversality constraints are given.Secondly, with the description of the neighboring optimal trajectory existence theory(NOTET), the neighboring optimal control(NOC)algorithm is derived by taking the second order partial derivations with the necessary conditions and transversality conditions. The revised terminal constraints are reversely integrated to the initial time and the perturbations of the co-states are further expressed with the states deviations and terminal constraints modifications.Thirdly, the simulations of two different scenarios are carried out and the results prove the effectiveness and optimality of the proposed method.展开更多
文摘僵尸网络(Botnet)是一种从传统恶意代码形态进化而来的新型攻击方式,为攻击者提供了隐匿、灵活且高效的一对多命令与控制信道(Command and Control channel,C&C)机制,可以控制大量僵尸主机实现信息窃取、分布式拒绝服务攻击和垃圾邮件发送等攻击目的。该文提出一种与僵尸网络结构和C&C协议无关,不需要分析数据包的特征负载的僵尸网络检测方法。该方法首先使用预过滤规则对捕获的流量进行过滤,去掉与僵尸网络无关的流量;其次对过滤后的流量属性进行统计;接着使用基于X-means聚类的两步聚类算法对C&C信道的流量属性进行分析与聚类,从而达到对僵尸网络检测的目的。实验证明,该方法高效准确地把僵尸网络流量与其他正常网络流量区分,达到从实际网络中检测僵尸网络的要求,并且具有较低的误判率。
基金supported by the National Natural Science Foundation of China(6150340861573374)
文摘The hypersonic interception in near space is a great challenge because of the target’s unpredictable trajectory, which demands the interceptors of trajectory cluster coverage of the predicted area and optimal trajectory modification capability aiming at the consistently updating predicted impact point(PIP) in the midcourse phase. A novel midcourse optimal trajectory cluster generation and trajectory modification algorithm is proposed based on the neighboring optimal control theory. Firstly, the midcourse trajectory optimization problem is introduced; the necessary conditions for the optimal control and the transversality constraints are given.Secondly, with the description of the neighboring optimal trajectory existence theory(NOTET), the neighboring optimal control(NOC)algorithm is derived by taking the second order partial derivations with the necessary conditions and transversality conditions. The revised terminal constraints are reversely integrated to the initial time and the perturbations of the co-states are further expressed with the states deviations and terminal constraints modifications.Thirdly, the simulations of two different scenarios are carried out and the results prove the effectiveness and optimality of the proposed method.