节点文献

DDoS型恶意软件防御策略的研究

Research on Containment Strategy Based on DDoS Malware

【作者】 赵海

【导师】 姚羽;

【作者基本信息】 东北大学 , 计算机应用技术, 2015, 硕士

【摘要】 互联网的迅速发展使人类社会进入到信息时代,随之而来的是越来越严重的网络安全问题。近年来,安全威胁事件逐年上升,尤其是恶意软件的大规模传播给国家和个人带来了巨大的损失。在诸多恶意软件安全问题中,DDoS型恶意软件无疑是最主要的安全威胁之一。因此,如何建立一个恰当的模型描述DDoS型恶意软件的传播行为就成为一个迫切的研究问题。通过对DDoS型恶意软件的研究发现,该恶意软件具有隐蔽性、破坏性、自动化和远程化的特点。DDoS型恶意软件可以通过漏洞大量传播,当其爆发时引起的破坏和经济损失都是难以估计的。为了描述DDoS型恶意软件的传播行为,本文建立了 SIRV模型,然后分析了此模型无病平衡点和有病平衡点的稳定性。在SIRV模型的基础上,为了更好地限制DDoS型恶意软件的大规模传播,本文提出了相对完整的抑制策略,引入了基于混合入侵检测系统的隔离策略,形成对DDoS型恶意软件的检测、隔离、清杀、免疫技术综合应用的完整体系。由于入侵检测系统是通过设置时间窗口来提高检测率,而大的时间窗口会产生系统时延。因此,本文提出了 SIRDQV时延传播模型,并且对SIRDQV时延模型进行了稳定性分析和Hopf分叉分析。其后,通过理论推导可以得到,SIRDQV模型存在一个临界时延值τ0,当系统时延小于τ0时,系统能够达到稳定状态,此时防御策略效果最佳;当系统时延大于或等于τ0时,系统就会出现Hopf分叉现象,此时DDoS型恶意软件的传播很难控制,提出的抑制策略失去效果。由此我们可以得出,为了更好地控制DDoS型恶意软件的传播,应当设置一个相对较小的时间窗口尺寸。最后,本文对SIRV模型和SIRDQV时延模型进行了数值模拟和仿真实验,实验结果证明了本文提出的抑制策略的有效性,验证了临界时延值τ0的存在。通过数值模拟和仿真实验的对比可以得到,两条曲线能够很好地拟合,证明了理论分析的正确性。

【Abstract】 With the rapid development of the Internet,the human society has come into the information age which followed by more and more serious network security issues.In recent years,incidents of security increased year by year.Especially,the massive spread of the malware has caused a great loss whether to the country or the individual.Among the many malware security problems,the DDoS malware is undoubtedly one of the most important security threats to the Internet.Therefore,it’s really an urgent problem that how to build a proper model to describe the propagation of DDoS malware.By studying the DDoS malware,it’s found that DDoS malware possess the characteristic of latent,damaged,automation and remote.It’s difficult to estimate the damage and economic loss when the DDoS malware outbreak because the DDoS malware can spread in large-scale through vulnerabilities.This dissertation constructs a model named SIRV in order to describe the propagation of DDoS malware.Besides,the stability of the disease-free equilibrium and the disease equilibrium point of the model is analyzed.In order to constrain the propagation of the DDoS malware,the paper proposed a complete containment strategy based on the model of SIRV.The isolation strategy is based on hybrid intrusion detection system.And the paper establish a complete system with the technology of detection,isolation,kill and immunization.A large time window may lead to time delay because the detection system improve the detection rate by setting a large time window among the hybrid intrusion detection system.So,the paper build a model named SIRDQV which has time delay.Besides,the stability of SIRDQV model and the Hopf bifurcation is analyzed.Then,there is a critical delay value τ0 in the SIRDQV model through theoretical analysis.The malware propagation system is stable when time delay is less than τ0.The containment strategy is effective at this moment.Otherwise,Hopf bifurcation appears and the system is unstable when time delay is equal to or more than τ0.The propagation of DDoS malware is out of control.Furthermore,the containment strategy is losing its effect.Therefore,it’s necessary to set a little time window of IDS in order to constrain the propagation of malware of DDoS-type.Finally,the paper gives out the numerical curves and simulation curves corresponding to the SIRV model and SIRDQV model.The experimental results prove the validity of the proposed suppression strategy and verify the existence of the critical delay value τ0.Through the comparison of numerical curve and simulation curve,the two curves can be well fitted,and also prove the correctness of theoretical analysis.

【关键词】 DDoS恶意软件防御策略时延稳定性分析
【Key words】 DDoSmalwarecontainment strategytime delaystability analysis
  • 【网络出版投稿人】 东北大学
  • 【网络出版年期】2018年 12期
  • 【分类号】TP393.08
  • 【下载频次】50
节点文献中: 

本文链接的文献网络图示:

本文的引文网络