Journal of Computer Applications ›› 2010, Vol. 30 ›› Issue (2): 529-531.

• Information security • Previous Articles     Next Articles

Comprehensive tolerance warning method of worm based on greedy algorithm

  

  • Received:2009-08-24 Revised:2009-10-04 Online:2010-02-10 Published:2010-02-01

基于贪婪算法的蠕虫综合容忍预警方法

左家亮1,寇雅楠2,杨任农2,张滢2,侯佩2,黄利斌2   

  1. 1. 西安市空军工程大学工程学院
    2.
  • 通讯作者: 左家亮

Abstract: Because there are a lot of difficulties in predicting the network worm exactly, a tolerant warning method based on greedy algorithm was proposed. The method took the characteristic of the spreading of worm into account, adopted some tolerant measures for some less harmful worms. A special data structure of datagram was designed, by statistical analysis of these datagram in the server, and could judge the threshold whether the warning system should be started up. The experimental simulation and theoretical analysis show that the method is feasible to some extent.

Key words: worm, tolerant warning, greedy algorithm

摘要: 针对网络蠕虫准确预警的困难性,综合蠕虫传播的特点,提出一种基于贪婪算法的容忍预警方法,对一些危害较小的可疑蠕虫采取一定的容忍机制,设计一个特定报文的数据段结构,在服务器端通过对这类报文的统计分析,计算出是否要启动预警的阈值。通过实验仿真和理论分析,表明此方案具有一定的可行性。

关键词: 蠕虫, 容忍预警, 贪婪算法