There is provided a method for tracking a
backbone network botnet based on a distributed space-time mechanism. According to the method, a traffic probe sends DNS data in traffic to a DNS abnormity traffic detection engine, which executes filtering by using a white
list and sends DNS access data to a Fast Flux DNS detection module to detect
a domain name with Fast Flux DNS characteristic. The traffic probe sends a TCP
handshake message and an end message that are in the traffic to a
macro distribution characteristic extraction engine to obtain
IP address data represented by
macro distribution characteristic, and an IP cluster executes clustering to obtain an
IP prefix for abnormal behavior, and sends the
IP prefix to a distributed mechanism determination engine to execute abnormity IP behavior
feature extraction. Filter
processing of a secondary probe is executed on the
domain name with Fast Flux DNS characteristic and the abnormity IP behavior feature, and the filtered result is inputted to an
iterator and iterated to output intermediate node information; the iteration is executed repeatedly by the secondary probe and the
iterator until there is no output from the secondary probe, and at the moment, the intermediate node information is a trackable
botnet node with the highest hierarchy.