• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2011, Vol. 33 ›› Issue (4): 19-24.doi: 10.3969/j.issn.1007130X.2011.

• 论文 • Previous Articles     Next Articles

A Worm Dectection System Based on Process Traffic Behaviors

XIAO Fengtao1,WANG Wei2,LIU Bo1,CHEN Xin1   

  1. (1.School of Computer Science,National University of Defense Technology,Changsha 410073;
    2.Corps 61198,Fuzhou 350003,China)
  • Received:2009-03-02 Revised:2009-06-23 Online:2011-04-25 Published:2011-04-25

Abstract:

With the propagation speed getting faster and faster, the damages caused by worms are getting more and more serious. To detect worms quickly, three wormrelated process traffic behaviors are described: the total amount of source port in wormlike traffic, the change frequency of source port in wormlike traffic and the ratio of wormlike traffic and total traffic for a single process. And based on the three behaviors, a worm detection system based on process traffic behaviors is presented and its definitions, framework design and key implementation are also introduced. Finally, through experimenting with the worms and normal applications in the real world, the system is proved to be able to detect worms quickly and correctly, and has only few false positives.

Key words: 蠕虫检测;进程流量行为;蠕虫行为;行为检测