摘要
该文分析了网络蠕虫的工作机制和扫描策略,根据蠕虫传播时引起的网络流量异常特征,设计了一种检测蠕虫病毒的方案,提出采用无级别分布式检测和SNMP技术抑制蠕虫传播的方法,利用探针检测引起网络流量异常的主机,与中心服务器配合迅速抑制异常流量扩散。实践表明,此方法能够有效地防止网络中蠕虫病毒的传播,保障网络资源的合理使用。
The mechanism and strategy of worm were analyzed. One basal settlement for detecting network worm was presented according to abnormal behavior of worm in spreading. It is presented that taking advantage of Stepiess Distributed Monitor and SNMP technique to prevent spreading of worms, using probes to find out the host which is abnormal and cooperate with monitor center to control it quickly. Practice shows that this method can prevent worm spreading effectively, and ensures network resource used in reason.
出处
《计算机安全》
2008年第12期121-124,共4页
Network & Computer Security