节点文献
Internet蠕虫传播及预警的研究
Research on Propagation and Warning of Worms in Internet
【作者】 姜汇军;
【导师】 李汉菊;
【作者基本信息】 华中科技大学 , 计算机系统结构, 2006, 硕士
【摘要】 Internet蠕虫以其快速、多样化的传播方式不断给网络世界带来灾害。与传统的主机病毒相比,Internet蠕虫具有更强的繁殖能力和破坏能力。因此,对Internet蠕虫的传播进行有效的建模并进行预警的研究具有非常重大的意义。蠕虫传播模型可以分为两种类型,即连续时间的模型和离散时间的模型。分析了典型的连续时间模型和AAWP(Analytical Active Worm Propagation)离散时间模型。设计了DTWP(Discrete Time Worm Propagation)模型,该模型是在AAWP模型的基础上增加了对抗蠕虫的考虑,在具体实现过程中对对抗蠕虫存在的四种情况都分别进行了分析。matlab仿真实验显示DTWP模型比AAWP模型能更好地预测蠕虫的传播趋势。互联网具有开放性的特点,没有完善的预测机制保证互联网络节点不受未知Internet蠕虫的攻击,传统基于单机的病毒预防技术对Internet蠕虫的预警并不适用。因此,设计了一种基于P2P的Internet蠕虫预警系统。系统采用P2P对等结构,各节点地位相同,节点加入退出灵活,整个系统中不存在计算瓶颈以及单点失效问题。系统在对网络中已知蠕虫进行预警的同时,从网络TCP流量中分析出可疑流量,并对可疑流量进行相似性分析,从而对未知蠕虫进行预警。另外,系统还能从初诊为蠕虫的可疑流量中自动提取蠕虫特征代码并在系统中广播,从而使当前未知蠕虫相对于系统中的各个检测节点来讲成为可疑蠕虫。因此,系统还具有预警的智能性。在Windows 2000操作系统下,基于JXTA中间件进行了基于P2P的Internet蠕虫预警系统的原型实现。测试结果表明,系统能够对网络中的未知蠕虫进行预警提示。
【Abstract】 Internet worms threaten to Internet continuously with the quick and various propagation modes. Compared with traditional host viruses, Internet worms have the better propagation and bring more damage. Therefore, it is very valuable to model the spread of Internet worms and study the warning system.Worm propagation models can be mainly divided into two types, which are the model with continuous time and the model with discrete time. The typical models with continuous time and the AAWP (Analytical Active Worm Propagation) model with discrete time are analyzed. Based on comparison between the two types of models, DTWP (Discrete Time Worm Propagation) model is proposed, which is the improvement of AAWP model and considers the situation of anti-worms. The simulation result in matlab suggests that Compared with AAWP model, DTWP model can provide better understanding and prediction of the upper propagation trend of Internet worms.Internet has the opening characteristic. There is no perfect prediction mechanism to assure that the nodes in Internet will not be attacked by unknown Internet worms. Thereby, traditional virus intrusion detections are not well-suited for the warning of Internet worms. Then, an Internet worms warning system based on P2P architecture is presented. The system uses the P2P architecture and all the nodes of the system have the same positions. So in our system, not only can the nodes add or quit flexibly, but also there is no computing bottleneck or single error problem, which should be considered by the security system. At the same time, the system analyzes TCP flows at the early time of worms appearing, gets suspicious flows, then does comparability analysis to these suspicious flows, and thus can warn the unknown worms. Additionally, the module of analyzing worm characteristic codes in the system can distill worm characteristic codes from suspicious flows, which makes the current unknown worm become the known one. In this way, it is intellective to warn worms in the system. Based on JXTA middleware, implementation of the system archetype is achieved in the Windows 2000 operation system. The testing result indicates that the system can warn the unknown worms in Internet.
【Key words】 Worm; Propagation Model; Scanning Strategy; Epidemic Model; Warning System;
- 【网络出版投稿人】 华中科技大学 【网络出版年期】2008年 03期
- 【分类号】TP393.08
- 【被引频次】7
- 【下载频次】209