首页 | 本学科首页   官方微博 | 高级检索  
     检索      

一种新的蠕虫检测和控制方法
引用本文:李胜利,王杰,韩宗芬,陶智飞.一种新的蠕虫检测和控制方法[J].华中科技大学学报(自然科学版),2007,35(3):38-41.
作者姓名:李胜利  王杰  韩宗芬  陶智飞
作者单位:华中科技大学,计算机科学与技术学院,湖北,武汉,430074
摘    要:在分析网络蠕虫连接请求和网络正常连接请求差异的基础上,提出一种新的蠕虫检测和控制方法.该方法针对网络蠕虫攻击特定端口以及攻击地址发散的特性,采用基于端口的多工作集区分网络蠕虫连接请求和网络正常连接请求,在蠕虫控制中使用多延迟队列处理可疑连接请求,避免了不同端口流量之间的相互影响;针对网络正常连接请求的暂时突发特征,利用令牌桶控制多延迟队列的输出,缩短了正常连接请求在延迟队列中的停留时间.测试表明,在主机感染了蠕虫后,新方法将误报率从85%降低到12%,对正常连接请求的平均延迟时间从95.4s降低到5.6s.

关 键 词:蠕虫检测  控制  误报率  延迟  蠕虫检测  控制方法  control  detection  method  平均延迟时间  误报率  感染  主机  测试  停留时间  输出  令牌桶  利用  特征  影响  端口流量  处理  延迟队列  使用
文章编号:1671-4512(2007)03-0038-04
修稿时间:02 10 2006 12:00AM

A novel method for detection and control of worms
Li Shengli,Wang Jie,Han Zongfen,Tao Zhifei.A novel method for detection and control of worms[J].JOURNAL OF HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY.NATURE SCIENCE,2007,35(3):38-41.
Authors:Li Shengli  Wang Jie  Han Zongfen  Tao Zhifei
Institution:College of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
Abstract:A novel method for worm detection and control is proposed after the difference between worm and normal connection requests was analyzed. Considering the worm characters of attacking unique port and dispersed IP addresses,the method uses port-based multiple work sets to identify worm connection requests in worm detection process,and employs multiple delay queues to process the suspicious connection requests in worm control process to avoid influence of traffic of different ports.Aiming at the normal connection character of ephemeral bursting out,the method takes advantage of token bucket to control the output of delay queues to shorten the period of staying in the delay queue of normal requests.Tests results show that for infected hosts,the false positive was reduced from 85 % to 12 % and the average delay time of normal connection requests was shortened from 95.4 seconds to 5.6 seconds by using new methods.
Keywords:worm detection  control  false positive  delay
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号