首页 | 本学科首页   官方微博 | 高级检索  
     检索      

An Overlay Network for Monitoring Activities of Computer Viruses
作者姓名:Li Ying  Cao Yiqun  Qiu Ben  Jiao Jian  Shan Xiuming  Ren Yong
作者单位:School of Business,SUN YATSEN University, Guangzhou 510275, China; Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;Department of Electronic Engineering, Tsinghua University, Beijing 100084, China
基金项目:国家重点基础研究发展计划(973计划)
摘    要:To accurately track computer viruses, an overlay network that monitors the activities of viruses is constructed. Identifying and locating nodes infected by virus on network is achieved by a naming system in which a node in the network is mapped to a unique serial number of the hard -drive. By carefully monitoring and recording sensitive commu- nication between local system and remote nodes on the network, and suspicious operations on files that originate from remote nodes and entered via some form of file transfer, activities of viruses in both local and network level are recorded and ready for future analysis. These data can also be used in analysis of the mechanism of a computer virus as well as its spreading mode and pattern.

关 键 词:计算机病毒  覆盖网络  监测  网络节点  命名系统  硬盘驱动器  活动构造  病毒感染

An Overlay Network for Monitoring Activities of Computer Viruses
Li Ying,Cao Yiqun,Qiu Ben,Jiao Jian,Shan Xiuming,Ren Yong.An Overlay Network for Monitoring Activities of Computer Viruses[J].Engineering Sciences,2008,6(1):52-58.
Authors:Li Ying  Cao Yiqun  Qiu Ben  Jiao Jian  Shan Xiuming and Ren Yong
Institution:[1]School of Business,SUN YAT-SEN University, Guangzhou 510275, China; [2]Department of Electronic Engineering, Tsinghua University, Beijing 100084, China
Abstract:To accurately track computer viruses, an overlay network that monitors the activities of viruses is constructed. Identifying and locating nodes infected by virus on network is achieved by a naming system in which a node in the network is mapped to a unique serial number of the hard drive. By carefully monitoring and recording sensitive communication between local system and remote nodes on the network, and suspicious operations on files that originate from remote nodes and entered via some form of file transfer, activities of viruses in both local and network level are recorded and ready for future analysis. These data can also be used in analysis of the mechanism of a computer virus as well as its spreading mode and pattern.
Keywords:overlay network  virus  observation  DNS
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《工程科学》浏览原始摘要信息
点击此处可从《工程科学》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号