摘要
为解决结构化P2P网络中蠕虫发现时间长、准确率低的问题,提出了基于蜜罐技术的蠕虫发现策略.通过在P2P节点的文件索引哈希表中设置代表蜜罐节点地址信息的(K,V)对,将P2P蠕虫引入蜜罐中,并通过设置过滤名单提高P2P蠕虫的发现准确率.通过在模拟环境中的实验和对比,证明了该发现策略能够在P2P蠕虫爆发后的第一轮感染过程中将蠕虫引入蜜罐并准确的识别出P2P蠕虫.为结构化对等网络的蠕虫发现提供了新的方法.
A new strategy of P2P worm detection based on honeypot in structured Peer-to-Peer network is put forwad out, which aims to solve the problems of long detection time, low rate of accuracy when detecting worm in the structured P2P network. Setting information (K,V) of honeypot address in file index hash table of P2P node, this strategy attracts P2P worm into honeypot and improves P2P worm detecting accuracy through adjusting filtrating list. The results show that P2P worm can be attracted into honeypot in the first infection and can be detected accurately in the experiment. It provides a new method for detecting P2P worm in the structured Peer-to-Peer network.
出处
《东南大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2008年第A01期100-103,共4页
Journal of Southeast University:Natural Science Edition
基金
国家科技支撑计划资助项目(2007BAH08B01)
关键词
P2P
蜜罐
P2P蠕虫
发现策略
peer-to-peer
honeypot
P2P worm
detection strategy