节点文献

蠕虫检测技术研究进展

Research and development of worm detection technologies

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 向郑涛陈宇峰董亚波鲁东明

【Author】 XIANG Zheng-tao1, CHEN Yu-feng1,2, DONG Ya-bo2, LU Dong-ming2 (1. Computer Center, Hubei Automotive Industries Institute, Shiyan 442002, China; 2. College of Computer Science and Technology, Zhejiang University, Hangzhou 310027, China)

【机构】 湖北汽车工业学院计算中心浙江大学计算机科学与技术学院

【摘要】 对蠕虫检测技术的进展进行了研究。由于能检测未知蠕虫,异常检测已成为蠕虫检测的重要发展方向。被动检测采用故意设计为有缺陷的系统HoneyPot,用来吸引攻击者、收集攻击信息并进行深度分析。主动检测对正常主机和蠕虫主机的混和流量进行处理,包括基于连接载荷和基于蠕虫行为的检测。分析并讨论了各类方法的特点和适用性,提出目前的检测技术需要更为有效的蠕虫检测指标,并基于正常主机和蠕虫主机在流量自相似性的差异,给出了相应的实时检测指标选择思路。

【Abstract】 The worm detection technologies are discussed. Anomaly detection will be a promising development because of the ability to detect unknown worms. For passive detection, the HoneyPot system designed deliberately with vulnerabilities is used to attract atta- ckers, collect attack information and process analysis. Active detection methods can process the mixed traffics of benign hosts and worm hosts, including the payload-based and behavior-based worm detection methods. The characters and applicability of each method are discussed. The viewpoint that more effective worm detection indices are needed for detection methods is proposed. Based on the diffe- rences of traffic self-similarity between benign hosts and worm hosts, the idea on how to select real-time detection indices is interpreted.

【基金】 国家自然科学基金项目(60503061);湖北省自然科学基金项目(2006ABA039);湖北省教育厅科学研究计划基金项目(D200623002)。
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2009年05期
  • 【分类号】TP309.5
  • 【被引频次】13
  • 【下载频次】256
节点文献中: 

本文链接的文献网络图示:

本文的引文网络