WANG Ping, FANG Bin-xing, YUN Xiao-chun. Large scale network worm detection using automatic signature extraction[J]. 2006, (6): 87-93.DOI:
基于自动特征提取的大规模网络蠕虫检测
摘要
蠕虫由于传播速度很快在网络中造成了严重的危害
对蠕虫进行自动的快速检测成了一项必需的研究。研究了在大规模网络中
利用流量异常发现模块从网络中发现异常数据集
然后自动进行特征提取
进而将特征更新到特征检测的特征库中进行特征检测的方法
实现对未知蠕虫的检测。本系统能够快速地发现新的疫情
作为蠕虫的自动防御的基础。
Abstract
Worms had done serious harm to the computer networks due to their propagating speeds.The research was necessary to detect worms quickly and automatically.In large scale networks
flux based anomaly found module was used to screen out anomalous network data set
and automatic signature extraction was processed in succession
then its signa-ture was updated to the signature database of the signature based detection module
thus
the approach to detect unknown worms was realized.Novel epidemic can be found effectively
and the whole system is the fundament of worm automatic defense.