【24h】

Dynamic control of worm propagation

机译:蠕虫传播的动态控制

获取原文

摘要

In a computer network, network security is accomplished using elements like firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm in priori to detect the attack. Modern day viruses like Code red, Sapphire and Nimda spread very fast. For example, Sapphire can double its size and infect more than 90% of the vulnerable hosts within 10 minutes. Therefore it is impractical if not impossible for human mediated responses to these modern day fast spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control is an effective method in containing the damage. In this paper we propose a state space feedback control model to detect and control the spread of these viruses by measuring the number of connections an infected host makes. The objective of the mechanism is to slow down the spreading velocity of a worm by controlling (delaying) the total number of connections made by an infected host. As expected, the model showed that the sooner the infection is detected the faster the reduction of the spreading velocity. Additionally, the deployment of a controller at different levels (host and firewall) has shown to be very promising.
机译:在计算机网络中,网络安全是通过使用防火墙,主机,服务器,路由器,入侵检测系统和蜜罐等元素来实现的。这些网络元素需要事先了解蠕虫的性质或异常情况才能检测到攻击。诸如红色代码,蓝宝石和Nimda之类的现代病毒传播速度非常快。例如,蓝宝石可以将其大小增加一倍,并在10分钟内感染90%以上的易受攻击主机。因此,对于人类介导的对这些现代快速传播病毒的反应,如果不是不可能的话,这是不切实际的。几项流行病学研究表明,自动跟踪资源使用和控制是控制破坏的有效方法。在本文中,我们提出了一种状态空间反馈控制模型,通过测量受感染主机建立的连接数来检测和控制这些病毒的传播。该机制的目的是通过控制(延迟)被感染主机建立的连接总数来减慢蠕虫的传播速度。如预期的那样,该模型表明,越早检测到感染,传播速度的降低速度就越快。此外,在不同级别(主机和防火墙)上部署控制器已显示出非常有前途的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号