A Classification Method and Implementation of Trojan and BotNet Infected User Based on Threat Matrix Model
Xiaoping Dai, Yao Li · 2019
with the rapid development of the Internet, the problem of cyber security has become increasingly serious. Trojan viruses and botnet programs play an important role in the Internet black industry chain. How to deal with cyber security incidents quickly and efficiently is a problem that needs to be solved. It has been found that the malware infected users are widely distributed and have diverse types, which cause great difficulties for cybersecurity experts to handle the threats. Based on practical cybersecurity incident handling experience, this paper proposes a User-Event Threat Matrix Model to define the infected users, and implement a classification method based on machine learning algorithm. So that we could find out the high-risk infected users and pay more attention to them.