节点文献

网络蠕虫传播与控制研究

Study on Propagation and Control of Internet Worms

【作者】 张运凯

【导师】 马建峰;

【作者基本信息】 西安电子科技大学 , 计算机应用技术, 2005, 博士

【摘要】 随着网络系统应用及复杂性的增加,网络蠕虫成为网络系统安全的重要威胁。网络蠕虫的研究已经成为近年来国际上在网络安全和信息安全领域最活跃的研究方向之一。对网络蠕虫结构、扫描策略、攻击方法的分析是防范网络蠕虫传播的前提条件,传播模型和控制策略的建立是防范蠕虫的根本保证和核心内容。针对现有网络蠕虫传播模型和控制策略中存在的不完善之处,本文结合人们防范自然界中传染病(SARS)的方法,对蠕虫传播模型进行了较为实际的改造,提出了基于隔离策略的网络蠕虫传播模型。针对多子网网络环境下防火墙对网络蠕虫传播的控制作用,提出了基于防火墙的蠕虫传播与控制模型。实验结果表明,本文提出的一系列控制策略都取得了良好的效果。归纳起来,本文的研究成果主要表现在以下几个方面:1.重新审视了现有的网络蠕虫定义。现有的定义不够准确,忽略了人的因素,不能概括目前已出现的网络蠕虫。再加上网络蠕虫采用的新技术会不断出现,网络蠕虫新的特点还会不断出现,但有两点基本特征是不会变的,即通过网络传播、自我复制。分析、比较各种恶意代码的特点,给出了其相同点和不同之处。2.详细分析了网络蠕虫的传播机制。对网络蠕虫的扫描方法、攻击方法进行了深入的研究。通过分析几个有代表性的网络蠕虫实例,得出了网络蠕虫的实体结构,为清除以及防御网络蠕虫打下基础。3.提出了两个基于隔离策略的网络蠕虫传播模型。第一个模型基于经典的Kermack-Mckendrick模型,在考虑主机的恢复时,包括了易感主机的恢复。第二个模型基于SEIR模型,考虑了网络蠕虫出生率和死亡率的影响。4.提出了一个基于多层次防火墙的企业网网络蠕虫综合控制系统。该系统在企业网络边缘、各子网间和用户主机上分别布置多层次的防火墙系统,并配合网络蠕虫检测与控制系统、网络防病毒系统等构成综合网络蠕虫控制系统。5.提出了基于防火墙的蠕虫传播与控制模型。针对多子网网络环境下防火墙对网络蠕虫传播的控制作用,提出了此模型。通过分析网络蠕虫在各子网内传播以及子网间交互传播,利用防火墙减小各子网间蠕虫的交互感染率,使网络蠕虫的传播得到了抑制。6.给出了一个新的无尺度网络的生成算法。综合利用了节点接入时的成本、局部信息。用无尺度网络拓扑生成器Brite模拟了Witty蠕虫的传播,验证了无尺度网络上网络蠕虫传播不存在类似随机网络上的传播阈值。

【Abstract】 With the explosive growth of network applications and complexity, the threat of Internet worms against network security becomes increasingly serious. In recent years, the study on Internet worms has become one of the most active research topics in the field of network security and information security in the world. In order to restrain Internet worms, we should first analyze their structure, scanning strategy and attack methods. Moreover, the essential guarantee and kernel content of defending them is to estalish their propagation models and control strategies.To overcome the faultiness of the available propagation models and control strategies, by combining the control method of natural epidemic (SARS), we actually improve the traditional propagation models in this dissertation, and then propose a new worm propagation model based on quarantine strategy. In view of the control of the firewall to network worms under many subnets, we also propose a worm propagation and control model based on the firewall. The experimental results illustrate the effectiveness and good performance of our control strategies.In sum, the main research fruits achieved in this thesis are given as follows. By studying current Internet worm’s definitions, it is found that the existing definitions are inaccurate; that is to say, these definitions neglect the human factors and can not generalize actual worms. Moreover, new technologies that worms use are ceaselessly appearing, and new characteristics of Internet worms may incidentally ceaselessly appear. However, their basic characteristics can not change, i.e. propagation through network and self-duplication.The propagation mechanism of Internet worms is analyzed minutely. The scanning and attack methods are carried through in-depth researches. By analyzing some representative worm cases, the entitative structure of worms is elicited, and prepares the base of cleaning and defending Internet worms.Two Internet worm propagation models based on the quarantine strategy are proposed. The first one, based on the classic Kermack-Mckendrick model, considers the recovery of susceptible hosts when we defend worms. The second one, based on the SEIR model, considers the birth rate and death rate of Internet worms.A worm control system of multi-level firewall enterprise network is proposed. This system installs multi-level firewall system respectively among the enterprise network edges, each subnets and terminals, and cooperates with worm detection and control system, network anti-virus system and so on to form the integrated worm control system.In view of the control of the firewall to network worms under many subnets, a model of the worm propagation and control model based on firewall is proposed. This model reduces the cross infection rate among subnets through the firewall and

  • 【分类号】TP393.08
  • 【被引频次】28
  • 【下载频次】1478
  • 攻读期成果
节点文献中: