基于动态基线分析方法的网络蠕虫检测机制的研究  被引量:5

On Network Worm Detection Mechanism Based on Dynamic Baseline Analysis

在线阅读下载全文

作  者:马艳春[1] 肖创柏[1] 

机构地区:[1]北京工业大学,北京100022

出  处:《华北科技学院学报》2008年第1期94-97,111,共5页Journal of North China Institute of Science and Technology

摘  要:提出了一种基于NetFlow的动态基线的蠕虫检测新方法。该方法利用NetFlow网络信息监测工具,每五分钟采集一次各通讯端口的信息,以其通讯端口、时间、流量三个维度所建立的信息基线过滤与基线偏离的信息,便可筛选出符合蠕虫行为的信息数据,进而找出可能的蠕虫及受感染的节点。According to the characteristics of network attacks, the author collected the information about NetFlow containing char- acteristics of the worm and put forward a new method of worm detection based on a dynamic baseline of NetFlow. The method used NetFlow information network monitoring tools to collect the information of communications port every five minutes. Through the deviations of the baseline and the selection of information baseline on the basis of three dimensions of communication port, time and flow, we can get the information and data of worm behavior, and thereby identify possible worm and the infected node. The experimental results show that the method can accurately detect worm attacks and this mechanism will be able to play a role at the beginning of a new worm attack.

关 键 词:网络安全 网络蠕虫 基线分析 网络管理 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象