• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2011, Vol. 33 ›› Issue (4): 19-24.doi: 10.3969/j.issn.1007130X.2011.

• 论文 • 上一篇    下一篇



  1. (1.国防科学技术大学计算机学院,湖南 长沙 410073;2.福州61198部队,福建 福州 350003)
  • 收稿日期:2009-03-02 修回日期:2009-06-23 出版日期:2011-04-25 发布日期:2011-04-25
  • 作者简介:肖枫涛(1981),男,河南沁阳人,博士生,研究方向为网络与信息安全。王维(1972),女,湖南浏阳人,工程师,研究方向为网络与信息安全。刘波(1973),男,江西九江人,博士生,副研究员,研究方向为网络与信息安全。陈新(1981),男,江西景德镇人,博士生,研究方向为网络与信息安全。
  • 基金资助:


A Worm Dectection System Based on Process Traffic Behaviors

XIAO Fengtao1,WANG Wei2,LIU Bo1,CHEN Xin1   

  1. (1.School of Computer Science,National University of Defense Technology,Changsha 410073;
    2.Corps 61198,Fuzhou 350003,China)
  • Received:2009-03-02 Revised:2009-06-23 Online:2011-04-25 Published:2011-04-25



关键词: 蠕虫检测, 进程流量行为, 蠕虫行为, 行为检测


With the propagation speed getting faster and faster, the damages caused by worms are getting more and more serious. To detect worms quickly, three wormrelated process traffic behaviors are described: the total amount of source port in wormlike traffic, the change frequency of source port in wormlike traffic and the ratio of wormlike traffic and total traffic for a single process. And based on the three behaviors, a worm detection system based on process traffic behaviors is presented and its definitions, framework design and key implementation are also introduced. Finally, through experimenting with the worms and normal applications in the real world, the system is proved to be able to detect worms quickly and correctly, and has only few false positives.

Key words: 蠕虫检测;进程流量行为;蠕虫行为;行为检测