首页 | 本学科首页   官方微博 | 高级检索  
     

主动良性蠕虫和混合良性蠕虫的建模与分析
引用本文:周翰逊,赵宏.主动良性蠕虫和混合良性蠕虫的建模与分析[J].计算机研究与发展,2007,44(6):958-964.
作者姓名:周翰逊  赵宏
作者单位:1. 东北大学信息科学与工程学院,沈阳,110004
2. 东北大学软件中心,沈阳,110004
基金项目:国家自然科学基金 , 国家高技术研究发展计划(863计划)
摘    要:自从1988年Morris蠕虫爆发以来,网络蠕虫就在不断地威胁着网络的安全.传统防范措施已不再适用于蠕虫的防治,使用良性蠕虫来对抗蠕虫正成为一种新的应急响应技术.良性蠕虫的思想就是将恶意的蠕虫转化成良性的蠕虫,而且该良性蠕虫还可以运用相同的感染机制免疫主机.这种方法可以主动地防御恶意蠕虫并且在没有传统的蠕虫防御框架下仍具有潜在的部署能力.首先,分别将主动良性蠕虫和混合良性蠕虫划分成3个子类;然后,基于两因素模型分别对主动良性蠕虫和混合良性蠕虫的3个子类进行建模,推导了在有延迟以及无延迟的情况下6类良性蠕虫的传播模型;最后,通过仿真实验验证了传播模型.更进一步,基于仿真结果讨论了每种良性蠕虫抑制恶意蠕虫的效果,并且得到如下结论:在相同的感染条件下,复合型的混合良性蠕虫抑制蠕虫传播的效果最好.

关 键 词:网络安全  主动良性蠕虫  混合良性蠕虫  蠕虫建模  两因素模型  良性蠕虫  混合  建模与分析  Analysis  蠕虫传播  复合型  条件  感染机制  效果  结果讨论  实验验证  仿真  传播模型  情况  无延迟  因素模型  划分  能力  框架  蠕虫防御
修稿时间:2006-09-16

Modeling and Analysis of Active-Benign Worms and Hybrid-Benign Worms
Zhou Hanxun,Zhao Hong.Modeling and Analysis of Active-Benign Worms and Hybrid-Benign Worms[J].Journal of Computer Research and Development,2007,44(6):958-964.
Authors:Zhou Hanxun  Zhao Hong
Affiliation:1. School of Information Science and Engineering, Northeastern University, Shenyang 110004; 2 .Software Center of Northeastern University, Shenyang 110004
Abstract:Since the Morris worm occurred in 1988, worms have threatened the network persistently, the traditional anti-virus technologies no longer scale to deal with the worm threat, and benign worms become a new active countermeasure. The idea of benign worm is to transform a malicious worm into an anti-worm which spreads itself using the same mechanism as the original worm and immunizes a host. This method allows for an active measure to malicious worms that can potentially be deployed with no additional infrastructure in place. First of all, an active-benign worm and a hybrid-benign worm are classified into three sub-types, respectively. Then, three sub-types of the active-benign worm and the hybrid-benign worm are modeled respectively based on the two-factor model, and the models of six types of benign worms are derived under the circumstances of no delay time and of delay time. Finally, the simulation validates the models. Furthermore, the effect of each type containing the spread of worms is discussed based on the results. And there comes the conclusion that a composition-hybrid-benign worm is the most effective approach for containing the propagation of worms under the same infectious condition.
Keywords:network security  active-benign worm  hybrid-benign worm  worm modeling  two-factor model
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号