摘要
提出了一个用于反向追踪大规模网络蠕虫传播的虚拟实验环境,能够用于网络蠕虫检测和防御实验。实验环境使用虚拟机技术,虚拟大量主机和网络设备参加,尽量符合网络实际。在可控的范围内,使用真实的感染代码引发大规模蠕虫的爆发,观测蠕虫的传播过程。实验环境中可以发现蠕虫的传播特性,实时收集网络蠕虫的流量数据和感染过程。
For the detection and defense of large scale Internet worm outbreaks, a convenient and safe experimental environment capable of running real worm becomes an important work to observe large scale worm infection, intrusion and propagation. It can be a large scale worm test bed for forensic evidence. A large-scale worm propagation experiments environment for tracing algorithm was proposed, which was an isolated environment that could run related experiments. To conform as much as possible to the actual network, the experimental environment used virtual machine technology, simulated a large number of hosts and network equipments. In this environment, large-scale worm outbreaks within the controllable scope could be triggered, the propagation process of the worm, experiment detection and defense techniques could be observed, the worm propagation characteristics such as scanning method and propagation process could be discovered, and the network traffic and propagation process could be collected real-timely. After network traffic was investigated, speculation algorithm was launched for reconstructing out patient zero and propagation path of the worm. Then actual worm propagation process could be captured and compared with the results of tracing algorithm.
出处
《计算机应用》
CSCD
北大核心
2007年第11期2696-2698,共3页
journal of Computer Applications
基金
国家自然科学基金资助项目(90204014)
吉林大学种子基金项目
关键词
蠕虫
在线追踪
培养皿
worm
online tracing
Petri dish