P2P僵尸网络是一种新型网络攻击方式,因其稳定可靠、安全隐蔽的特性被越来越多地用于实施网络攻击,给网络安全带来严峻挑战.为深入理解P2P僵尸网络工作机理和发展趋势,促进检测技术研究,首先分析了P2P僵尸程序功能结构,然后对P2P僵尸网络结构进行了分类,并分析了各类网络结构的特点;在介绍了P2P僵尸网络生命周期的基础上,着重阐述了P2P僵尸网络在各个生命周期的工作机制;针对当前P2P僵尸网络检测研究现状,对检测方法进行了分类并介绍了各类检测方法的检测原理;最后对P2P僵尸网络的发展趋势进行了展望,并提出一种改进的P2P僵尸网络结构.
P2P botnet is a new type of network attack. Because of reliable, safe and hidden characteristics, P2P botnets are increasingly used in network attacks, which have posed serious challenges to network security. In order to further understand the mechanism and the development trend of P2P botnets and promote the detection technology research, this paper first analyzes the functional structure of P2P botnets program, then introduces the classification of P2P botnets structure, and analyzes the characteristics of the various types of P2P botnets structure. Based on introducing the life cycle of P2P botnets, this paper focuses on the working mechanism of the P2P botnets in each life stage. Besides, the detection methods are classified and the principle of each detection method is introduced, which is based on the current research of P2P botnet detection. Finally, the development trend of P2P botnets is calculated and an improved P2P botnet structure is proposed.