首页 | 本学科首页   官方微博 | 高级检索  
     

基于改进蚁群算法的多态蠕虫特征提取
引用本文:黄辉 郭帆 徐淑芳. 基于改进蚁群算法的多态蠕虫特征提取[J]. 计算机应用, 2013, 33(12): 3494-3498
作者姓名:黄辉 郭帆 徐淑芳
作者单位:江西师范大学 计算机信息工程学院,南昌 330022
基金项目:江西省自然科学基金资助项目
摘    要:多态蠕虫特征提取是基于特征的入侵检测的难点,快速提取出精确程度更高的多态蠕虫特征对于有效防范蠕虫的快速传播有着重要的作用。针对层次式的多序列匹配(HMSA)算法进行多序列比对的时间效率较低和由迭代方法提取出的特征不够精确等问题,提出了基于改进蚁群算法的多态蠕虫特征提取方法antMSA。该方法首先对蚁群的搜索策略进行了相应的改进,并将改进后的蚁群算法引入到奖励相邻匹配的全局联配(CMENW)算法中,利用蚁群算法快速收敛能力,在全局范围内快速生成较好解,提取出多态蠕虫的特征片段;然后将其转化为标准入侵检测系统(IDS)规则,用于后期防御。实验表明,改进后的蚁群算法能够较好地克服基本蚁群算法的停滞现象,扩大搜索空间,能够有效提高特征提取的效率和质量,降低误报率。

关 键 词:蚁群算法  序列比对  特征提取  入侵检测  多态蠕虫  
收稿时间:2013-06-18
修稿时间:2013-08-16

Polymorphic worms signature extraction based on improved ant colony algorithm
HUANG Hui GUO Fan XU Shufang. Polymorphic worms signature extraction based on improved ant colony algorithm[J]. Journal of Computer Applications, 2013, 33(12): 3494-3498
Authors:HUANG Hui GUO Fan XU Shufang
Affiliation:College of Computer Information Engineering, Jiangxi Normal University, Nanchang Jiangxi 330022, China
Abstract:Polymorphic worms signature extraction is a critical part of signature-based intrusion detection. Extracting precise signatures quickly plays an important role in preventing the spread of the worms. Since the classical Hierarchical Multi-Sequence Alignment (HMSA) algorithm has bad time performance in extracting signatures when multiple sequences alignment was used and the extracted signatures were not precise enough, a new automatic signature extraction method called antMSA was proposed based on the improved ant optimal algorithm. The search strategy of the ant group was improved, and then it was introduced to the Contiguous Matches Encouraging Needleman-Wunsch (CMENW) algorithm to get a better solution quickly in global range by using the rapid convergence ability of ant colony algorithm. The signature fragments were extracted and converted into the standard rules of the intrusion detection system for subsequent defense. The experimental results show that the new method solves the stagnation problem of the classical ant optimal algorithm, extends the search space, extracts signatures more efficiently and precisely, and reduces the false positive rate and the false negative rate.
Keywords:Ant Colony Algorithm (ACA)   sequence alignment   signature extraction   intrusion detection   polymorphic worm
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号