期刊文献+

基于公共特征集合的网络蠕虫特征码自动提取 被引量:3

Automatic extraction of Internet worm signature based on common feature set
下载PDF
导出
摘要 作为连接检测与遏制的桥梁,特征码的自动提取在蠕虫对抗中发挥着重要作用。介绍了传统的网络蠕虫特征码提取算法,分析了它们的工作机理和主要缺陷,提出了一种基于公共特征集合的提取算法,它支持低复杂度提取与优化,也支持灵敏性和特异性之间的权衡,在应对背景噪声和交叉传染方面具有显著优势。 Serving as the bridge that links detection and containment, automatic signature extraction has played an important role in anti-worm. Traditional Internet worm signature extraction algorithms were introduced. Based on the analysis of their mechanisms and major defections, an extraction algorithm based on common feature set was presented. It supported low complexity extraction and optimization, as well as the tradeoff between sensitivity and specialization, and had remarkable superiority in dealing with background noise and cross infection.
出处 《计算机应用》 CSCD 北大核心 2005年第7期1540-1542,共3页 journal of Computer Applications
基金 国家自然科学基金资助项目(60403033)
关键词 蠕虫 特征码 自动提取 worm signature automatic extraction
  • 相关文献

参考文献3

  • 1MOORE D, SHANNON C, VOELKER GM, et al.Internet quarantine: requirements for containing self-propagating code[A]. IEEE INFOCOM 2003[C]. 2003,22(1) : 1901 - 1910.
  • 2KIM H , KARP B . Autograph : Toward Automated , Distributed Worm Signature Detection[A]. USENIX Security Symposium[C],2004.271 - 286.
  • 3KREIBICH C, CROWCROFT J. Honeycomb: creating intrusion detection signatures using honeypots [J].Computer Communication Review, 2004, 34(1):51 - 56.

同被引文献9

引证文献3

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部