计算机应用 ›› 2010, Vol. 30 ›› Issue (2): 529-531.

• 信息安全 • 上一篇    下一篇

基于贪婪算法的蠕虫综合容忍预警方法

左家亮1,寇雅楠2,杨任农2,张滢2,侯佩2,黄利斌2   

  1. 1. 西安市空军工程大学工程学院
    2.
  • 收稿日期:2009-08-24 修回日期:2009-10-04 发布日期:2010-02-10 出版日期:2010-02-01
  • 通讯作者: 左家亮

Comprehensive tolerance warning method of worm based on greedy algorithm

  • Received:2009-08-24 Revised:2009-10-04 Online:2010-02-10 Published:2010-02-01

摘要: 针对网络蠕虫准确预警的困难性,综合蠕虫传播的特点,提出一种基于贪婪算法的容忍预警方法,对一些危害较小的可疑蠕虫采取一定的容忍机制,设计一个特定报文的数据段结构,在服务器端通过对这类报文的统计分析,计算出是否要启动预警的阈值。通过实验仿真和理论分析,表明此方案具有一定的可行性。

关键词: 蠕虫, 容忍预警, 贪婪算法

Abstract: Because there are a lot of difficulties in predicting the network worm exactly, a tolerant warning method based on greedy algorithm was proposed. The method took the characteristic of the spreading of worm into account, adopted some tolerant measures for some less harmful worms. A special data structure of datagram was designed, by statistical analysis of these datagram in the server, and could judge the threshold whether the warning system should be started up. The experimental simulation and theoretical analysis show that the method is feasible to some extent.

Key words: worm, tolerant warning, greedy algorithm