[1]巩永旺.基于扫描流量统计的本地网蠕虫检测方法[J].计算机技术与发展,2011,(07):145-148.
GONG Yong-wang.Local Network Worm Detection Method Based on Scan Traffic Statistics[J].,2011,(07):145-148.
点击复制
基于扫描流量统计的本地网蠕虫检测方法(
)
《计算机技术与发展》[ISSN:1006-6977/CN:61-1281/TN]
- 卷:
-
- 期数:
-
2011年07期
- 页码:
-
145-148
- 栏目:
-
安全与防范
- 出版日期:
-
1900-01-01
文章信息/Info
- Title:
-
Local Network Worm Detection Method Based on Scan Traffic Statistics
- 文章编号:
-
1673-629X(2011)07-0145-04
- 作者:
-
巩永旺1; 2
-
[1]盐城工学院信息工程学院[2]南京邮电大学计算机学院
- Author(s):
-
GONG Yong-wang
-
[1]School of Information Engineering,Yancheng Institute of Technology[2]College of Computer,Nanjing University of Posts and Telecommunications
-
- 关键词:
-
蠕虫检测; 扫描流量统计; 马尔科夫不等式; 坎泰利不等式; 扫描包特征
- Keywords:
-
worm detection; scan traffic statistical; Markov's inequality; Cantelli's inequality; scan packets profile
- 分类号:
-
TP393
- 文献标志码:
-
A
- 摘要:
-
为了准确检测外网蠕虫对本地网的传播,在研究蠕虫扫描行为模式的基础上,提出一种基于扫描流量统计的本地网蠕虫检测方法,并给出蠕虫检测方法实现的总体思路、关键算法和检测过程。该检测方法分为异常流量检测和扫描包特征匹配检测两个步骤,即首先使用马尔科夫和坎泰利不等式在网络边界检测进入本地网的扫描流量,提取异常流量中的可疑扫描包的特征;然后监控本地网,检测与可疑扫描包特征相匹配的本地网扫描活动,进而判定本地网是否感染外网蠕虫。分析与初步实验证明,该方法能够检测准确检测外网蠕虫对本地网的传播
- Abstract:
-
In order to detect propagation of network worm from exterior network to local network accurately,a worm detection method based on scan traffic statistics was proposed after researching worm scan patterns,and the general ideal,key algorithms and worm detection process of which was discussed.The worm detection method consisted abnormal traffic detection and scan packets profile matching detection,which firstly detected abnormal scan traffic from exterior network to local network by the Markov's and Cantelli's inequalities,abstracting doubtful scan packets profiles from the abnormal traffic,and then through monitoring the local network and detecting the scan activities that matched the doubtful scan packets profiles,warned the propagation of worms from exterior network.The analysis and preliminary experimental results proved that the method can detect network worm from exterior network accurately
备注/Memo
- 备注/Memo:
-
国家自然科学基金(60874091); 江苏省“六大人才高峰”高层次人才项目(SJ209006)巩永旺(1976-),男,山东曹县人,讲师,博士研究生,研究方向为计算机网络、复杂网络及其信息安全技术
更新日期/Last Update:
1900-01-01