计算机科学 ›› 2011, Vol. 38 ›› Issue (6): 101-105.

• 计算机网络与信息安全 • 上一篇    下一篇

蠕虫预警及非线性传播模型优化

佟晓筠,王翥   

  1. (哈尔滨工业大学(威海)计算机科学与技术学院 威海264209);(哈尔滨工业大学(威海)信息科学与工程学院 威海264209)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家自然科学基金(60973162),山东省自然科学基金(ZR2009GM037),山东省科技攻关项目(2010GGX10132),哈尔滨工业大学(威海)校科学研究基金(HIT(WH) 2009年)资助。

Worm Warning and Optimization of Nonlinear Propagation Model

TONG Xiao-jun,WANG Zhu   

  • Online:2018-11-16 Published:2018-11-16

摘要: 目前已有一些蠕虫检测系统利用蠕虫传播特性进行检测,误报率高,不能对大范围网络进行检测。为此,首先对蠕虫传播模型进行了分析和优化,提出了新蠕虫分布式传播模型。针对该模型提出了分布式蠕虫检测技术,亦即采用基于规则的检测方法监控网络蠕虫,控制台管理和协调多个检测端的工作。实验结果表明,该方法能够很好地预警蠕虫的传播行为并进行监控和报警,具有高检测率和低误报率。

关键词: 蠕虫,蠕虫传播模型优化,蠕虫预警,分布式蠕虫检测

Abstract: At present there arc some worm intrusion detection systems which detect network worms only by using worm propagation properties and have high false alarm rate. This paper analyzed worm non-linear propagation models, realized the optimization of worm model, and proposed distributed worm propagation model. Then a distributed worm detection technology was designed according to the distributed worm propagation model. The system uses rule-based detection method to monitor network worms, and the console side manages and coordinates detection work of the client sides. The experimental results show that the technology is a good solution to worm warning and worm detection, which can give an alarm with high detection rate and low false alarm rate.

Key words: Worm, Propagation model optimisation of worm, Worm warning, Distributed worm detection

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!