浏览全部资源
扫码关注微信
1. 哈尔滨工业大学计算机网络与信息安全技术研究中心
2. 国家计算机网络应急技术处理协调中心
纸质出版日期:2007
移动端阅览
辛毅, 方滨兴, 贺龙涛, 等. 基于通信特征分析的蠕虫检测和特征提取方法的研究[J]. 通信学报, 2007,(12):1-7.
XIN Yi1, FANG Bin-xing1, HE Long-tao2, et al. Worm detection and signature extraction based on communication characteristics[J]. 2007, (12): 1-7.
辛毅, 方滨兴, 贺龙涛, 等. 基于通信特征分析的蠕虫检测和特征提取方法的研究[J]. 通信学报, 2007,(12):1-7. DOI:
XIN Yi1, FANG Bin-xing1, HE Long-tao2, et al. Worm detection and signature extraction based on communication characteristics[J]. 2007, (12): 1-7. DOI:
提出了一种基于通信特征分析的蠕虫检测与特征提取技术
在解析蠕虫传播过程中特有的通信模式的基础上
评估通信特征集合间的相似度
通过检测传染性来检测蠕虫
这种方法具有更高的检测精度、通用性和适应性。在此基础上设计了启发式检测体系结构
利用盲目跟踪、意向跟踪和锁定跟踪从通信协议、通信序列和通信内容3个层次逐级排除非蠕虫通信
筛选出蠕虫报文组
提取出蠕虫特征码。这种技术大幅缩减了采集量和分析量
能在高强度背景噪声的干扰快速检测蠕虫并提取出相应的特征。
Worm detection and signature extraction was presented based on analysis of similar communication character-istics
which identifies the distinct communication pattern of worm spread
and evaluates the similarity metric of commu-nication characteristic sets
and detects worms by detecting their infectivity with higher detection precision
generality and adaptability.Based on this
a heuristic detection framework is designed
which eliminates non-worm traffic from protocol
sequence
and content in three levels via blind
intent and lock track
then filters out worm packets and extracts signatures.The technique reduces data collection volume and analysis cost dramatically
and can detection worm and ex-tract signature quickly in the environment with high strength background noise.
0
浏览量
324
下载量
4
CSCD
关联资源
相关文章
相关作者
相关机构