作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (21): 147-150. doi: 10.3969/j.issn.1000-3428.2009.21.048

• 安全技术 • 上一篇    下一篇

IM蠕虫检测方案的设计与实现

赵彬彬1,2,张玉清2,刘 宇2   

  1. (1. 西安电子科技大学计算机网络与信息安全教育部重点实验室,西安 710071; 2. 中国科学院研究生院国家计算机网络入侵防范中心,北京 100043)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-11-05 发布日期:2009-11-05

Design and Implementation of IM Worm Detection Method

ZHAO Bin-bin1,2, ZHANG Yu-qing2, LIU Yu2   

  1. (1. Key Lab of Computer Networks and Information Security, Ministry of Education, Xidian University, Xi’an 710071; 2. National Computer Network Intrusion Protection Center, Graduate University of Chinese Academy of Sciences, Beijing 100043)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-11-05 Published:2009-11-05

摘要: 针对日益增多的IM蠕虫,提出一种基于IM蠕虫传播特性的检测方案,在网关处监测所有的IM消息,通过统计可疑消息的增长情况来检测蠕虫,采用动态队列减少存储量,并利用用户验证模块对可疑消息进行确认,提高检测的准确性。实验表明,该方案在保证检测成功率的基础上,能有效减轻服务器负担,节约存储资源,并且减少了对正常通信的影响。

关键词: IM蠕虫, 行为特征, 扼杀, 检测

Abstract: This paper presents a method of detecting Instant Messaging(IM) worm on the base of its propagation characteristics. It monitors all the IM messages at the gateway and detects worm through statistical growth of suspicious messages. It adopts dynamical queues to reduce the storage and implements a user confirmation module to verify suspicious messages which improves the detection accuracy. Experiments show that on the basis of assuring the detection accuracy, it can effectively reduce the burden of the server, save the memory resources and reduce the impact on normal communication.

Key words: Instant Messaging(IM) worm, behavior characteristic, stifling, detection

中图分类号: