CN101699787B - 一种用于对等网络的蠕虫检测方法 - Google Patents
一种用于对等网络的蠕虫检测方法 Download PDFInfo
- Publication number
- CN101699787B CN101699787B CN 200910185425 CN200910185425A CN101699787B CN 101699787 B CN101699787 B CN 101699787B CN 200910185425 CN200910185425 CN 200910185425 CN 200910185425 A CN200910185425 A CN 200910185425A CN 101699787 B CN101699787 B CN 101699787B
- Authority
- CN
- China
- Prior art keywords
- peer
- worm
- network
- peer network
- traffic
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 59
- 238000000034 method Methods 0.000 claims abstract description 35
- 238000004458 analytical method Methods 0.000 claims abstract description 18
- 238000005516 engineering process Methods 0.000 claims abstract description 18
- 239000003795 chemical substances by application Substances 0.000 claims description 44
- 230000005856 abnormality Effects 0.000 claims description 10
- 238000001914 filtration Methods 0.000 claims description 7
- 238000012300 Sequence Analysis Methods 0.000 claims description 5
- 238000004364 calculation method Methods 0.000 claims description 4
- 238000012544 monitoring process Methods 0.000 claims description 3
- 238000012545 processing Methods 0.000 claims description 3
- 239000000872 buffer Substances 0.000 claims description 2
- 230000008878 coupling Effects 0.000 claims 6
- 238000010168 coupling process Methods 0.000 claims 6
- 238000005859 coupling reaction Methods 0.000 claims 6
- 230000003542 behavioural effect Effects 0.000 claims 2
- 206010024774 Localised infection Diseases 0.000 claims 1
- 208000015181 infectious disease Diseases 0.000 claims 1
- 230000002159 abnormal effect Effects 0.000 abstract description 13
- 230000007123 defense Effects 0.000 abstract description 5
- 230000006399 behavior Effects 0.000 description 17
- 230000008569 process Effects 0.000 description 11
- 241000700605 Viruses Species 0.000 description 9
- 238000011160 research Methods 0.000 description 7
- 238000010586 diagram Methods 0.000 description 5
- 230000007246 mechanism Effects 0.000 description 5
- 238000004891 communication Methods 0.000 description 3
- 230000005540 biological transmission Effects 0.000 description 2
- 230000006378 damage Effects 0.000 description 2
- 206010033799 Paralysis Diseases 0.000 description 1
- 230000002776 aggregation Effects 0.000 description 1
- 238000004220 aggregation Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000009395 breeding Methods 0.000 description 1
- 230000001488 breeding effect Effects 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 230000006835 compression Effects 0.000 description 1
- 238000007906 compression Methods 0.000 description 1
- 230000008602 contraction Effects 0.000 description 1
- 230000008260 defense mechanism Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 230000001066 destructive effect Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000009977 dual effect Effects 0.000 description 1
- 238000000605 extraction Methods 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000002452 interceptive effect Effects 0.000 description 1
- 230000009191 jumping Effects 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
- 230000000452 restraining effect Effects 0.000 description 1
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (4)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN 200910185425 CN101699787B (zh) | 2009-11-09 | 2009-11-09 | 一种用于对等网络的蠕虫检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN 200910185425 CN101699787B (zh) | 2009-11-09 | 2009-11-09 | 一种用于对等网络的蠕虫检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101699787A CN101699787A (zh) | 2010-04-28 |
CN101699787B true CN101699787B (zh) | 2013-01-02 |
Family
ID=42148233
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN 200910185425 Expired - Fee Related CN101699787B (zh) | 2009-11-09 | 2009-11-09 | 一种用于对等网络的蠕虫检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN101699787B (zh) |
Families Citing this family (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101867571A (zh) * | 2010-05-12 | 2010-10-20 | 上海电机学院 | 基于协同多个移动代理的智能网络入侵防御系统 |
CN103428212A (zh) * | 2013-08-08 | 2013-12-04 | 电子科技大学 | 一种恶意代码检测及防御的方法 |
CN104901850B (zh) * | 2015-06-12 | 2018-08-31 | 国家计算机网络与信息安全管理中心广东分中心 | 一种恶意代码终端感染机器网络定位方法 |
GB2545744A (en) * | 2015-12-24 | 2017-06-28 | British Telecomm | Malicious network traffic identification |
CN107086944B (zh) * | 2017-06-22 | 2020-04-21 | 北京奇艺世纪科技有限公司 | 一种异常检测方法和装置 |
CN108173834A (zh) * | 2017-12-25 | 2018-06-15 | 北京计算机技术及应用研究所 | 终端指纹技术识别“一卡通”网络终端 |
CN111027063A (zh) * | 2019-09-12 | 2020-04-17 | 北京安天网络安全技术有限公司 | 防止终端感染蠕虫的方法、装置、电子设备及存储介质 |
CN111125703A (zh) * | 2019-12-24 | 2020-05-08 | 沈阳航空航天大学 | 一种基于幂级数rnn的多态网络蠕虫特征码提取 |
-
2009
- 2009-11-09 CN CN 200910185425 patent/CN101699787B/zh not_active Expired - Fee Related
Also Published As
Publication number | Publication date |
---|---|
CN101699787A (zh) | 2010-04-28 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101699787B (zh) | 一种用于对等网络的蠕虫检测方法 | |
CN107454109B (zh) | 一种基于http流量分析的网络窃密行为检测方法 | |
Cui et al. | SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks | |
Zhou et al. | A survey of coordinated attacks and collaborative intrusion detection | |
AU2013272211B2 (en) | Path scanning for the detection of anomalous subgraphs, anomaly/change detection and network situational awareness | |
US20130263259A1 (en) | Analyzing response traffic to detect a malicious source | |
CN106790186A (zh) | 基于多源异常事件关联分析的多步攻击检测方法 | |
Narang et al. | PeerShark: flow-clustering and conversation-generation for malicious peer-to-peer traffic identification | |
Kheir et al. | Botsuer: Suing stealthy p2p bots in network traffic through netflow analysis | |
Dai et al. | Eclipse attack detection for blockchain network layer based on deep feature extraction | |
CN116760636A (zh) | 一种未知威胁的主动防御系统和方法 | |
Signorini et al. | Advise: anomaly detection tool for blockchain systems | |
Lee et al. | Real-time analysis of intrusion detection alerts via correlation | |
Thakur et al. | Detection and prevention of botnets and malware in an enterprise network | |
CN108337219A (zh) | 一种物联网防入侵的方法和存储介质 | |
CN107315952A (zh) | 用于确定应用程序可疑行为的方法和装置 | |
Uddin et al. | Intrusion detection system to detect DDoS attack in gnutella hybrid P2P network | |
CN100377534C (zh) | 一种网络蠕虫检测系统及方法 | |
Fei et al. | The abnormal detection for network traffic of power iot based on device portrait | |
Xue et al. | Design and implementation of a malware detection system based on network behavior | |
Cheetancheri et al. | A distributed host-based worm detection system | |
Prashanth et al. | Using random forests for network-based anomaly detection at active routers | |
Tarng et al. | The analysis and identification of P2P botnet's traffic flows | |
Yu et al. | Peer-to-peer system-based active worm attacks: Modeling, analysis and defense | |
Lyu et al. | AGCM: A multi-stage attack correlation and scenario reconstruction method based on graph aggregation |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20100428 Assignee: Jiangsu Nanyou IOT Technology Park Ltd. Assignor: NANJING University OF POSTS AND TELECOMMUNICATIONS Contract record no.: 2016320000217 Denomination of invention: Worm detection method used for peer-to-peer network Granted publication date: 20130102 License type: Common License Record date: 20161118 |
|
LICC | Enforcement, change and cancellation of record of contracts on the licence for exploitation of a patent or utility model | ||
EC01 | Cancellation of recordation of patent licensing contract |
Assignee: Jiangsu Nanyou IOT Technology Park Ltd. Assignor: NANJING University OF POSTS AND TELECOMMUNICATIONS Contract record no.: 2016320000217 Date of cancellation: 20180116 |
|
EC01 | Cancellation of recordation of patent licensing contract | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20130102 |
|
CF01 | Termination of patent right due to non-payment of annual fee |