节点文献

网络性能监控及病毒预警机制的研究

Research of Network Performance Supervision and Virus Warning Mechanism

【作者】 李荣

【导师】 赵东范;

【作者基本信息】 吉林大学 , 计算机软件与理论, 2005, 硕士

【摘要】 本文给出了吉林大学创新基金项目“网络性能监控及病毒预警机制的研究”的部分功能实现。随着现代信息技术的迅猛发展,计算机网络已在我国社会生活的各个方面得到了广泛的普及和应用,但是近年来计算机病毒开始在我国出现并迅速泛滥,它对整个网络的安全运行构成极大的威胁。因此,如何防止计算机病毒入侵计算机网络和保证网络的安全已成为人们面临的一个重要且紧迫的课题。目前,国内有很多针对计算机病毒进行查找、清除的工具软件,但是在病毒对网络造成重大影响之前,在路由器层面,发现网络用户感染病毒的迹象,提供预警机制的产品却很少见。因此,本项目的研究在一定程度上弥补了这方面的空白,具有一定的实际应用价值。本项目研究基于SNMP 协议,监控网络性能,对计算机病毒在网络中的扩散提供一个预警机制,从而增强网络的可用性,提高运行效率。INTERNET 是基于TCP/IP 协议的网络,网络互连时使用路由器将不同的网络连接起来,一个网络流入、流出的数据包都要经过路由器处理。本项目对流经路由器的数据包进行收集、处理、分析、统计,从而监测网络当前的工作状态、运行效率。本项目的难点在于数据的采集,即从路由器中采集有用的数据,然后对采集到的数据进行分析,得出相关结论。研究的关键是找出相关的网络病毒的特征指标。本文首先对项目“网络性能监控及病毒预警机制的研究”以及本文主要完成的任务给出了简要的介绍。其次,对网络管理、简单网络管理协议SNMP 给出详细介绍。然后详细给出ASN.1 表示形式的处理,同时给出异常流量的分析和处理防范网络异常流量的方法,并且给出常见蠕虫病毒的Netflow 分析。最后,文中给出了网络性能预警系统的实现,给出用SNMP 采集和分析网络流量数据,并给出了基于AR 模型的网络流量异常检测方法。

【Abstract】 The thesis presents partial implementation of Creative Fund Project “Research of network performance supervision and virus warning mechanism”in Jilin University. With the rapid development of modern information technology, computer network has been widely used and prevalent in many aspects of our society. But computer virus has appeared and deluged in recent years.It poses a threat to the safe operation of the whole network.Therefore, how to prevent computer virus from intruding network and ensure the security of network has become an important and pressed task for people. The research of the thesis is based on SNMP(Simple Network Management Protocol) of TCP/IP-based network. It can supervise network performance and provide against the spread of computer virus in network. Consequently, it can enhance the usability of network and improve operational efficiency.Internet is TCP/IP-based. Router can be used to connect different network, therefore, router is indispensable network equipment. The datagram which flow into, outflow the network will be handeled by router. This project collects, handles, analyzes and calculates the datagram flowing through router, then supervises the present status and efficency of network. When supervising these data, if network administrator finds some anomalistic statistic data, such as CPU use ratio is too high, non-data traffic is extremely big, small traffic datagram fixed byte data is too much and visits to some port are frequent, he can find the evidence of virus inbreak. At this time, if warning is produced and people take actions, we can hold back the flooding of virus and prevent network paralysis. The difficulty of the project lies in data collection, namely to collect useful data from router, analyze it and draw conclusion. The key of research is to find characteristics of relevant network virus. As part of the project “research of network performance supervision and virus warning mechanism “, the work of the thesis consists of the following aspects. 1. Deal with ASN.1 form We have completed to decode ASN.1 form into integer and object identifier, as well as routine which can convert object value. 2. Netflow analysis of anomalistic traffic Netflow is a kind of data exchange means. A netflow stream is defined unidirectional datagram stream transmitted between a source IP address and destination IP address, and all the datagram have the same source and destination port number in transport layer. We can collect Netflow data through Cisco Netflow Collector offered by Cisco. We have done a lot of experiments and found many kinds of anomalistic traffic, including denial of service (Dos), distributed denial of service(DDos), network worm traffic and other anomalistic traffic. 3. Handle network anomalistic traffic To some extent, network anomalistic traffic will never disappear and there is no essential technical solution. We can use some technical means to analyze anomalistic traffic and reduce the impact and loss brought by it. The following methods and tools are adopted when analyzing anomalistic traffic. (1). Judge the direction of anomalistic traffic. (2). Collect and analyze netflow data. After analyzing the direction of anomalistic traffic, we can choose the proper network port to implement network configuration and collect netflow data flow into network. (3).Means dealing with anomalistic traffic a. Cut off connection b. Filter c. Static bland route filter

【关键词】 路由器SNMP网络性能计算机病毒
  • 【网络出版投稿人】 吉林大学
  • 【网络出版年期】2005年 07期
  • 【分类号】TP393.07
  • 【下载频次】355
节点文献中: 

本文链接的文献网络图示:

本文的引文网络