计算机应用 ›› 2013, Vol. 33 ›› Issue (02): 430-433.DOI: 10.3724/SP.J.1087.2013.00430

• 信息安全 • 上一篇    下一篇

基于局部变化性的网页篡改识别模型及方法

魏文晗1,邓一贵2   

  1. 1. 重庆大学 计算机学院,重庆 400044
    2. 重庆大学 信息与网络管理中心,重庆 400044
  • 收稿日期:2012-08-03 修回日期:2012-09-11 出版日期:2013-02-01 发布日期:2013-02-25
  • 通讯作者: 魏文晗
  • 作者简介:魏文晗(1986-),男,湖北天门人,硕士研究生,主要研究方向:计算机网络、信息安全;
    邓一贵(1971-),男,四川简阳人,高级工程师,博士,主要研究方向:计算机网络、信息安全、移动代理。
  • 基金资助:
    重庆市自然科学基金资助项目

Detection model and method of website defacements based on attributes partial changes

WEI Wenhan1,DENG Yigui2   

  1. 1. College of Computer Science, Chongqing University, Chongqing 400044, China
    2. Information and Campus Network Management Center, Chongqing University, Chongqing 400044, China
  • Received:2012-08-03 Revised:2012-09-11 Online:2013-02-01 Published:2013-02-25
  • Contact: WEI Wenhan

摘要: 针对传统的网页远程监控方式局限于静态网页的问题,本文提出一种适用于动态网页的基于规则的分类模型。该模型考虑到网页的局部变化性,首先根据历史页面的动态更新,划分网页的动态区域和静态区域;其次,对动态区域,根据历史特征计算相关阀值,对静态区域建立分块的MD5历史库;最后,根据定义的IF-THEN规则决定是否发送警报。实验表明,该模型能在更短时间内完成全站检测,对正常页面的误报率较低,对异常页面的检测率较高。

关键词: 网页篡改, 网站监测, 篡改检测, IF-THEN规则, 领域知识

Abstract: The traditional methods of website remote monitoring are limited to static webpages. A rule-based classifier for dynamic webpage was proposed. The method took the website partial changes into consideration, and divided the websites into the dynamic regions and the static regions according to the dynamic updates of the historical pages, and then calculated thresholds based on the historical features for dynamic regions and built history database of MD5 based on blocks for the static regions. Finally, it decided whether to send alarms according to the defined IF-THEN rules. The test results show that the model can scan the whole website in shorter time, get lower false detection rate for normal pages and higher detection rate for distorted pages.

Key words: Web defacement, website monitoring, defacement detection, IF-THEN rule, domain knowledge

中图分类号: