|
With the continuous development of computer and data communications technology, people's lives are also quick to enter the digital age, the establishment of computer networks, digital sharing of information and external resources to maximize. At the same time, however, the network to a computer virus has brought more favorable survival and propagation environment, China Internet Security statistics report shows that the types of complex computer virus to appear more and more frequent in the computer and on the network, the worm class malicious code the number increased by three percentage points compared to the same period last year. Exponential growth model in a network environment, the worm infection, a short period of time caused by the paralysis of the network system, development of computer networks as well as raising the level of virus writers, so that the traditional computer worm detection method is difficult to meet people information security needs. Therefore, the network environment, the detection and control of the worm has become the focus of the field of computer viruses. This paper first reviews the emergence and development of computer viruses, network worms, compare the differences and connections between computer viruses and network worms, given the definition of network worms, and the structure and function of the worm to make a further elaboration, Summary of existing worm detection and control technology in-depth study of worm propagation characteristics based on the analysis of the inadequacies of existing methods, the new method proposed a worm detection and control. The main work of this paper include: 1) in terms of network worm detection time model-based Bayesian network worm detection techniques, improved the original Bayes methods, make full use of Bayesian probability and statistics function to statistically perspective to analyze and solve the problem, consider the history of the state of the existing state to update the posterior probability prior probability, and the worm twice the time interval different, at different times of network traffic this principle Join the concept of time model, making more scientific and accurate analysis results; 2) on network worm control, two leaky bucket algorithm improvements, two leaky bucket algorithm based on the pre-buffer control technology, according to worm attack characteristics, the packet will be issued by the infected host into different delay queue by port number of the port to send packets to control the size of the bursty traffic, as a way to control the spread of the worm; 3) for the above network worms detection and control technology, the formation of a system, and build a network worm detection and control platform, to verify the feasibility and effectiveness of the proposed algorithm. Research summary, the proposed algorithm is feasible, and has high efficiency, as well as analysis of the problems, the prospect of the next step of the research work.
|