摘要
蠕虫由于传播速度很快在网络中造成了严重的危害,对蠕虫进行自动的快速检测成了一项必需的研究。研究了在大规模网络中,利用流量异常发现模块从网络中发现异常数据集,然后自动进行特征提取,进而将特征更新到特征检测的特征库中进行特征检测的方法,实现对未知蠕虫的检测。本系统能够快速地发现新的疫情,作为蠕虫的自动防御的基础。
Worms had done serious harm to the computer networks due to their propagating speeds. The research was necessary to detect worms quickly and automatically. In large scale networks, flux based anomaly found module was used to screen out anomalous network data set, and automatic signature extraction was processed in succession, then its signature was updated to the signature database of the signature based detection module, thus, the approach to detect unknown worms was realized. Novel epidemic can be found effectively, and the whole system is the fundament of worm automatic defense.
出处
《通信学报》
EI
CSCD
北大核心
2006年第6期87-93,共7页
Journal on Communications
基金
国家高技术研究发展计划("863"计划)基金资助项目(2001AA147010B)~~
关键词
计算机网络
蠕虫
特征检测
异常发现
特征提取
computer network
worm
signature detection
anomaly find
signature extraction