期刊文献+

基于失败连接流量偏离度的蠕虫早期检测方法

A Novel Approach for Early Detection of Worm Based on Failed Connection Flow Dissimilarity
下载PDF
导出
摘要 通过分析网络蠕虫攻击的特点,定义了能够反映蠕虫攻击特征的失败连接流量偏离度(FCFD)的概念,并提出了一种基于FCFD时间序列分析的蠕虫早期检测方法。该方法利用小波变换对FCFD时间序列进行多尺度分析,利用高频分量模极大值进行奇异点检测,从而发现可能的蠕虫攻击。同时给出了一种基于失败连接分析的蠕虫感染主机定位和蠕虫扫描特征提取方法。实验结果显示,该方法能够有效检测未知蠕虫的攻击。和已有方法相比,该方法具有更高的检测效率和更低的误报率。 On the basis of analyzing the features of worm attack, the concept of failed connections flow dissimilarity (FCFD) which reflects the variation of network flow caused by worms attack is defined, and a novel approach for early detection of worms is proposed. This approach analyzes the FCFD time series with multi resolution analysis of wavelet transform, detects singularity point through the local maxima of high frequencies, so to detect possible worm attack. A method to derive the list of likely infected hosts and extract possible worln scanning features is also proposed. The experiment shows that the approach can detect possible worms attack in real-time. Compared with existing methods, this approach is more sensitive in the early stage of worm propagation, and has a lower false positive rate.
出处 《计算机工程》 CAS CSCD 北大核心 2006年第15期22-24,33,共4页 Computer Engineering
基金 国家"863"计划基金资助项目(2003AA148010) 国家火炬计划基金资助项目(2005EB011484)
关键词 网络蠕虫检测 小波变换 奇异点检测 Network worm detection Wavelet transform Singularity detection
  • 相关文献

参考文献7

  • 1Zou C C,Gong W,Towsley D,et al.The Monitoring and Early Detection of Intemet Worms[J].IEEE/ACM Transactions on Networking,2005,13(5):961-974.
  • 2Chen Shigang,Ranka S.Detecting Intemet Worms at Early Stage[J].IEEE Journal on Selected Areas in Communications,2005,23(10):2003-2012.
  • 3Berk V H,Gray R S,Bakos G.Using Sensor Networks and Data Fusion for Early Detection of Active Worms[C].SPIE AeroSense Symp,Orlando,FL,2003.
  • 4He Hui,Zhang Hongli,Zhang Weizhe,et al.Early Warning of Active Worms Based on Multi-similarity[C].Proceedings of the Fourth International Conference on Machine Learning and Cybernetics,Guangzhou,2005-08:3876-3883.
  • 5Mallat S.A Theory for Multiresolution Signal Decomposition:The Wavelet Representation[J].IEEE Trans.on Pattern Analysis and Machine Intelligence,1989,11 (7):674-693.
  • 6Jump(R) Network Information Audit System (JAudit-N100)[EB/OL].http://www.jump.net.cn,2005-12.
  • 7Chen Shigang,Tang Yong.Slowing Down Intemet Worms[C].Proc.of the 24^th International Conference on Distributed Computing Systems,Tokyo,Japan,2004-03.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部