检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]西安交通大学电信学院网络所,西安710049 [2]西安建筑科技大学信控学院,西安710055
出 处:《计算机工程》2006年第15期22-24,33,共4页Computer Engineering
基 金:国家"863"计划基金资助项目(2003AA148010);国家火炬计划基金资助项目(2005EB011484)
摘 要:通过分析网络蠕虫攻击的特点,定义了能够反映蠕虫攻击特征的失败连接流量偏离度(FCFD)的概念,并提出了一种基于FCFD时间序列分析的蠕虫早期检测方法。该方法利用小波变换对FCFD时间序列进行多尺度分析,利用高频分量模极大值进行奇异点检测,从而发现可能的蠕虫攻击。同时给出了一种基于失败连接分析的蠕虫感染主机定位和蠕虫扫描特征提取方法。实验结果显示,该方法能够有效检测未知蠕虫的攻击。和已有方法相比,该方法具有更高的检测效率和更低的误报率。On the basis of analyzing the features of worm attack, the concept of failed connections flow dissimilarity (FCFD) which reflects the variation of network flow caused by worms attack is defined, and a novel approach for early detection of worms is proposed. This approach analyzes the FCFD time series with multi resolution analysis of wavelet transform, detects singularity point through the local maxima of high frequencies, so to detect possible worm attack. A method to derive the list of likely infected hosts and extract possible worln scanning features is also proposed. The experiment shows that the approach can detect possible worms attack in real-time. Compared with existing methods, this approach is more sensitive in the early stage of worm propagation, and has a lower false positive rate.
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.3