首页 | 本学科首页   官方微博 | 高级检索  
     

基于失败连接流量偏离度的蠕虫早期检测方法
引用本文:廖明涛,张德运,侯琳.基于失败连接流量偏离度的蠕虫早期检测方法[J].计算机工程,2006,32(15):22-24,3.
作者姓名:廖明涛  张德运  侯琳
作者单位:1. 西安交通大学电信学院网络所,西安,710049
2. 西安建筑科技大学信控学院,西安,710055
基金项目:高比容电子铝箔的研究开发与应用项目;国家火炬计划
摘    要:通过分析网络蠕虫攻击的特点,定义了能够反映蠕虫攻击特征的失败连接流量偏离度(FCFD)的概念,并提出了一种基于FCFD时间序列分析的蠕虫早期检测方法。该方法利用小波变换对FCFD时间序列进行多尺度分析,利用高频分量模极大值进行奇异点检测,从而发现可能的蠕虫攻击。同时给出了一种基于失败连接分析的蠕虫感染主机定位和蠕虫扫描特征提取方法。实验结果显示,该方法能够有效检测未知蠕虫的攻击。和已有方法相比,该方法具有更高的检测效率和更低的误报率。

关 键 词:网络蠕虫检测  小波变换  奇异点检测
文章编号:1000-3428(2006)15-0022-03
收稿时间:2006-03-09
修稿时间:2006-03-09

A Novel Approach for Early Detection of Worm Based on Failed Connection Flow Dissimilarity
LIAO Mingtao,ZHANG Deyun,HOU Lin.A Novel Approach for Early Detection of Worm Based on Failed Connection Flow Dissimilarity[J].Computer Engineering,2006,32(15):22-24,3.
Authors:LIAO Mingtao  ZHANG Deyun  HOU Lin
Affiliation:1. Institue of Network, School of Electronics and Information, Xi’an Jiaotong University, Xi’an 710049;
2. Institute of Information and Control Engineering, Xi’an University of Architecture &; Technology , Xi’an 710055
Abstract:On the basis of analyzing the features of worm attack,the concept of failed connections flow dissimilarity(FCFD) which reflects the variation of network flow caused by worms attack is defined,and a novel approach for early detection of worms is proposed.This approach analyzes the FCFD time series with multi resolution analysis of wavelet transform,detects singularity point through the local maxima of high frequencies,so to detect possible worm attack.A method to derive the list of likely infected hosts and extract possible worm scanning features is also proposed.The experiment shows that the approach can detect possible worms attack in real-time.Compared with existing methods,this approach is more sensitive in the early stage of worm propagation,and has a lower false positive rate.
Keywords:Network worm detection  Wavelet transform  Singularity detection
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号