作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (3): 165-167. doi: 10.3969/j.issn.1000-3428.2008.03.058

• 安全技术 • 上一篇    下一篇

FB-NBAS:一种基于流的网络行为分析模型

李 军,曹文君,李 杨   

  1. (复旦大学软件学院,上海 200433)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-02-05 发布日期:2008-02-05

FB-NBAS: A Flow-based Network Behavior Analysis Model

LI Jun, CAO Wen-jun, LI Yang   

  1. (School of Software, Fudan University, Shanghai 200433)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-02-05 Published:2008-02-05

摘要: 传统的入侵检测系统通常需要对攻击预先了解,在流量分析和异常检测方面存在不足。该文提出一种新的基于流的统计分析模型,通过构建网络的行为特征库,实时监测和发现网络异常,基于该分析技术设计和实现了一个网络监控系统原型。该原型可以监测和发现网络中可疑代码,并进行实时跟踪。

关键词: 网络监控, 网络行为, 行为分析

Abstract: Traditional Intrusion Detection Systems(IDSs) requires prior knowledge of attacks, loses effectiveness in flow analysis and abnormity detection. This paper proposes a new flow-based network behavior analysis model, which monitors and detects abnormity of network by building up a network behavior features base for each host. Based on this technology, a network monitor prototype system is designed and implemented. The system can detect malicious codes and track them in real time.

Key words: network monitor, network behavior, behavior analysis

中图分类号: