作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (7): 126-128. doi: 10.3969/j.issn.1000-3428.2008.07.044

• 安全技术 • 上一篇    下一篇

基于阴性选择的网络蠕虫抑制模型

洪 征,吴礼发,王元元   

  1. (解放军理工大学指挥自动化学院,南京 210007)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-04-05 发布日期:2008-04-05

Worm Containment Model Based on Negative Selection

HONG Zheng, WU Li-fa, WANG Yuan-yuan   

  1. (Institute of Command Automation, PLA University of Science and Technology, Nanjing 210007)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-04-05 Published:2008-04-05

摘要: 基于免疫系统的阴性选择机制,提出一种网络蠕虫抑制模型。通过主机的程序行为异常,检测蠕虫攻击并及时响应,允许主机进行大部分的正常网络通信,防止蠕虫通过主机继续传播。主机发出基于阴性选择过滤的网络服务请求,依据蠕虫的传播特征,网络主机之间相互协同,推断蠕虫所攻击的服务并进行限制。实验结果表明,该模型能有效检测并抑制传统蠕虫及拓扑蠕虫等传播隐秘的新型蠕虫。

关键词: 蠕虫, 人工免疫系统, 阴性选择

Abstract: Based on negative selection mechanism of the immune system, this paper proposes a worm containment model. By monitoring abnormal program behavior, the model effectively detects worms and makes reaction. The reaction policy contains worm propagation and allows the majority of normal traffic to proceed. Negative selection is used to filter service requests which the worm host sends out, and according to worm properties, hosts cooperate to determine and contain the services which the worm attacks. Experimental results indicate the model can detect and contain classical worms as well as emerging stealthy worms such as topological worms.

Key words: worm, artificial immune system, negative selection

中图分类号: