摘要
通过对目前几种蠕虫检测和抑制策略的分析比较,提出了一种改进的两轮蠕虫检测和抑制算法,论证了这种算法对快速和慢速蠕虫检测和抑制的有效性,同时考虑了正常网络行为对该算法的影响,大大降低了该算法的误报率。最后,仿真实验分析了该算法在正常网络背景和网络拥堵背景下的检测蠕虫效果,证明了该算法策略能够高效地检测和抑制蠕虫,同时具有较好的低误报性。
Based on the comparison and analysis of many worm containment strategy, a new and effective strategy of worm dynamic defense and containment which is named IWDC is proposed in this paper. The effectiveness for containing top-speed scan worm and slow-speed scan worm is demonstrated. The impact of normal network traffic on the containment strategy is also analyzed so that it brings clown false positives largely. The simulation results verify that improved two-rotation quarantine algorithm can contain worms effectively and create lower false alarms.
出处
《微计算机信息》
北大核心
2008年第16期224-226,235,共4页
Control & Automation
关键词
蠕虫抑制
蠕虫检测
失败连接
误报率
worm containment
worm detection
false connection
false alarms