首页> 外文会议>Information Security and Cryptology >Online Tracing Scanning Worm with Sliding Window
【24h】

Online Tracing Scanning Worm with Sliding Window

机译:滑动窗口在线跟踪扫描蠕虫

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Breaking out of network worms brings a tremendous damage to the Internet. Launch the worm defense and response can improve anti-attack capability of networks. Tracing worm propagation process after its outbreak can reconstruct not only the earliest infected nodes but also the timing order of victims been infected. Based on the improvement of existing offline worm tracing algorithm, we can realize the near real-time tracing for the propagation process of scanning worm: Network traffic data are real-time collected by the detection points from different LANs, then separated into continuous-time detection sliding windows; in every time window, we repeatedly and randomly collect paths that contain worm scanning and infected flow rate, reconstruct path of worm propagation in the current detection window. Results accumulated in sequential detection sliding windows continues doing feedback amendment, real-time reflect the process of worm propagation. we establish a virtual experimental environment of worm propagation and tracing to evaluate the algorithm. Tracing network worm propagation from the initial attack can inhibit continuous spread of the worm, ensure that no more host is infected by the worm, and provide basis for the determination of worm attack origin.
机译:突破网络蠕虫会给Internet带来巨大破坏。启动蠕虫的防御和响应可以提高网络的抗攻击能力。追踪蠕虫爆发后的传播过程,不仅可以重建最早的受感染节点,而且可以重建受感染者的时间顺序。在对现有离线蠕虫跟踪算法进行改进的基础上,可以实现对扫描蠕虫传播过程的近实时跟踪:网络流量数据由不同局域网的检测点实时采集,然后分成连续的检测滑动窗口;在每个时间窗口中,我们反复并随机地收集包含蠕虫扫描和感染流量的路径,在当前检测窗口中重建蠕虫传播的路径。顺序检测滑动窗口中累积的结果将继续进行反馈修正,实时反映蠕虫传播的过程。我们建立了蠕虫传播和跟踪的虚拟实验环境,以评估算法。从最初的攻击中跟踪网络蠕虫的传播可以抑制蠕虫的持续传播,确保不再有主机感染该蠕虫,并为确定蠕虫攻击源提供依据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号