僵尸网络是一种严重威胁网络安全的攻击平台。文章先给出僵尸网络的定义,然后分析其工作机制,命令与控制机制。针对当前主流的僵尸网络检测方法,按照不同的行为特征进行分类,根据僵尸网络的静态特征、动态特征以及混合特征,对当前的主要检测方法进行了归纳、分析和总结。并在文章最后提出,建立一个完备的僵尸网络检测模型需要将僵尸网络的动态特征检测模型与静态特征检测模型相互结合,而这才是僵尸网络检测模型未来发展的重点。
Botnets as a serious threat to network security attack platform,due to its difficult to find the controller,is favored by the majority of hackers.Based on a clear definition of zombie networks,this article first analyzes its command and control mechanism.Then it describes some of the popular methods of detecting botnets and analysis on the methods according to the dynamic features,static features and compound characteristics for classification.Finally,it is proposed that to establish the comprehensive botnet detection,the dynamic and static characteristics detections need to be combined,and this will make the bonet detection more effective and accurate.