【24h】

Dynamic Control of Worm Propagation

机译:蠕虫传播的动态控制

获取原文

摘要

In a computer network, network security is accomplished using elements like firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm in priori to detect the attack. Modern day viruses like Code red, Sapphire and Nimda spread very fast. For example, Sapphire can double its size and infect more than 90% of the vulnerable hosts within 10 minutes. Therefore it is impractical if not impossible for human mediated responses to these modern day fast spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control is an effective method in containing the damage. In this paper we propose a state space feedback control model to detect and control the spread of these viruses by measuring the number of connections an infected host makes. The objective of the mechanism is to slow down the spreading velocity of a worm by controlling (delaying) the total number of connections made by an infected host. As expected, the model showed that the sooner the infection is detected the faster the reduction of the spreading velocity. Additionally, the deployment of a controller at different levels (host and firewall) has shown to be very promising.
机译:在计算机网络中,使用防火墙,主机,服务器,路由器,入侵检测系统和蜂蜜罐等元素来完成网络安全。这些网络元素需要了解蠕虫的性质或异常,以检测攻击。现代日病毒如代码红色,蓝宝石和尼姆达传播非常快。例如,蓝宝石可以在10分钟内加倍其大小并感染超过90%的弱势主机。因此,如果人类介导对这些现代化的日期快速蔓延病毒,人类介导的反应是不可能的,这是不切实际的。几项流行性研究表明,资源使用和控制的自动跟踪是含有损坏的有效方法。在本文中,我们提出了一种状态空间反馈控制模型来通过测量感染的主机的连接数来检测和控制这些病毒的扩散。该机制的目的是通过控制(延迟)由受感染的宿主进行的连接总数减慢蠕虫的扩散速度。正如预期的那样,该模型表明,检测到感染越早较快的扩散速度的降低。此外,在不同级别(主机和防火墙)的控制器部署已显示非常有前景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号