首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于远程软件认证和序贯概率比分析的蠕虫检测
引用本文:郭强,张重阳.基于远程软件认证和序贯概率比分析的蠕虫检测[J].华中师范大学学报(自然科学版),2018,52(4):461-467.
作者姓名:郭强  张重阳
作者单位:1.中国海洋石油总公司信息技术中心, 北京 100010; 2.南京理工大学计算机科学与技术学院, 南京 210094
摘    要:针对仅认证方法无法检测到不在随机选择集合中的被感染节点,提出一种改进方法,应用序贯概率比分析(SPRA)和远程软件认证以检测蠕虫传播.首先,利用检测器观察无线传感器网络中的通信模式,识别正常流量中不会出现的连接链;然后,当探测器节点检测到蠕虫传播模式,则发起远程软件认证,且区域节点通过SPRA协作捕捉蠕虫传播.仿真结果验证了所提方法的有效性.与仅认证方法和支持向量回归(SVR)方法相比,所提方法的蠕虫检测鲁棒性更好.在蠕虫环境下,进行蠕虫检测和阻止所需的认证次数高于仅认证方法,低于SVR方法,总体开销较低.

关 键 词:序贯概率比分析    蠕虫检测    远程软件认证    无线传感器网络    认证次数  
收稿时间:2018-07-11

Research of worm detection based on remote software authentication and sequential probability ratio analysis
GUO Qiang,ZHANG Chongyang.Research of worm detection based on remote software authentication and sequential probability ratio analysis[J].Journal of Central China Normal University(Natural Sciences),2018,52(4):461-467.
Authors:GUO Qiang  ZHANG Chongyang
Institution:1.Information Technology Center, China National Offshore Oil Corporation, Beijing 100010, China;2.School of Computer Science and Technology, Nanjing University of Science and Technology, Nanjing 210094, China
Abstract:As the only authentication method can't detect infected nodes that is not in the random selection set, an improved method is proposed, which uses sequential probability ratio analysis (SPRA) and remote software authentication to detect worm propagation. Firstly, the detector is used to observe the communication mode in the wireless sensor network, and identify the connection chains that will not appear in the normal traffic. Then, when the probe node detects the worm propagation mode, the remote software authentication is initiated, and the regional nodes capture the worm propagation through the SPRA collaboration. The simulation results show the effectiveness of the proposed method. Compared with the only authentication method and the support vector regression (SVR) method, the proposed method has better robustness to worm detection. In worm environment, the number of authentication times required for worm detection and blocking is higher than that of the only authentication method, but lower than that of the SVR method. And the total cost is good.
Keywords:sequential probability ratio analysis  worm detection  remote software authentication  wireless sensor networks  number of authentication  
本文献已被 CNKI 等数据库收录!
点击此处可从《华中师范大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《华中师范大学学报(自然科学版)》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号