摘要
对蠕虫检测技术的进展进行了研究。由于能检测未知蠕虫,异常检测已成为蠕虫检测的重要发展方向。被动检测采用故意设计为有缺陷的系统HoneyPot,用来吸引攻击者、收集攻击信息并进行深度分析。主动检测对正常主机和蠕虫主机的混和流量进行处理,包括基于连接载荷和基于蠕虫行为的检测。分析并讨论了各类方法的特点和适用性,提出目前的检测技术需要更为有效的蠕虫检测指标,并基于正常主机和蠕虫主机在流量自相似性的差异,给出了相应的实时检测指标选择思路。
The worm detectiOn technologies are discussed. Anomaly detection will be a promising development because of the ability to detect unknown worms. For passive detection, the HoneyPot system designed deliberately with vuinerabilities is used to attract attackers, collect attack information and process analysis. Active detection methods can process the mixed traffics ofbenign hosts and worm hosts, including the payload-based and behavior-based worm detection methods. The characters and applicability of each method are discussed. The viewpoint that more effective worm detection indices are needed for detection methods is proposed. Based on the differences of traffic self-similarity between benign hosts and worm hosts, the idea on how to select real-time detection indices is interpreted.
出处
《计算机工程与设计》
CSCD
北大核心
2009年第5期1060-1064,共5页
Computer Engineering and Design
基金
国家自然科学基金项目(60503061)
湖北省自然科学基金项目(2006ABA039)
湖北省教育厅科学研究计划基金项目(D200623002)。
关键词
蠕虫检测
异常检测
被动检测
主动检测
蠕虫检测指标
worm detection
anomaly detection
passive detection
active detection
worm detection indices