摘要
蠕虫病毒是网络的主要威胁之一。实时流量采集和分析对于快速侦测和定位已感染蠕虫病毒的计算机具有重要意义。常见的蠕虫病毒监测方法如IDS和Sniff等,都存在难以全网监控、无法快速定位伪造IP地址的病毒源的缺点。分析了多种网络流量采集技术的优缺点,重点介绍了sFlow技术,并基于sFlow技术设计实现了一套园区网蠕虫病毒快速侦测系统。
Worm is one of the main threats of networks. It is important for us to collect and analyze network packets to find out infected computers quickly, It is difficult for normal Intemet worm detection technology, such as IDS and SNIFF, to monitor the whole campus network or to find out the infected computers which send packets with faked source IP address. The advantages and the disadvantages of network stream collect measures, especially sFlow are discussed, A new worm detection system for campus networks based on sFlow technology is introduced.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第2期346-348,共3页
Computer Engineering and Design