首页> 外文期刊>IEEE transactions on dependable and secure computing >Fast Worm Containment Using Feedback Control
【24h】

Fast Worm Containment Using Feedback Control

机译:使用反馈控制快速遏制蠕虫

获取原文
获取原文并翻译 | 示例

摘要

In a computer network, network security is accomplished using elements such as firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm a priori to detect the attack. Modern viruses such as Code Red, Sapphire, and Nimda spread quickly. Therefore, it is impractical if not impossible for human mediated responses to these fast-spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control provides an effective method to contain the damage. In this paper, we propose a novel security architecture based on the control system theory. In particular, we describe a state-space feedback control model that detects and control the spread of these viruses or worms by measuring the velocity of the number of new connections an infected host makes. The mechanism''s objective is to slow down a worm''s spreading velocity by controlling (delaying) the number of new connections made by an infected host. A proportional and integral (PI) controller is used for a continuous control of the feedback loop. The approach proposed here has been verified in a laboratory setup, and we were able to contain the infection so that it affected less than 5 percent of the hosts. We have also implemented a protocol for exchanging control-specific information between the network elements. The results from the simulation and experimental setup combined with the sensitivity analysis demonstrate the applicability and accuracy of the approach.
机译:在计算机网络中,使用防火墙,主机,服务器,路由器,入侵检测系统和蜜罐之类的元素来实现网络安全。这些网络元素需要先验地了解蠕虫的性质或异常,以检测攻击。诸如红色代码,蓝宝石和Nimda之类的现代病毒迅速传播。因此,对于人类介导的对这些快速传播的病毒的反应,即使不是不可能的,也是不切实际的。几个流行病研究表明,对资源使用和控制的自动跟踪提供了一种有效的控制损失的方法。在本文中,我们提出了一种基于控制系统理论的新型安全体系结构。特别是,我们描述了一种状态空间反馈控制模型,该模型通过测量受感染主机建立的新连接的数量来检测和控制这些病毒或蠕虫的传播。该机制的目的是通过控制(延迟)被感染主机建立的新连接的数量来减慢蠕虫的传播速度。比例积分(PI)控制器用于连续控制反馈回路。此处提出的方法已在实验室设置中得到验证,而且我们能够控制感染,因此感染率不到5%。我们还实现了一种协议,用于在网络元素之间交换特定于控制的信息。仿真和实验设置以及灵敏度分析的结果证明了该方法的适用性和准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号