摘要
在传统的入侵检测理论的基础上,研究了统计学概念模型系统熵,并结合蠕虫病毒的行为特征提出了指数熵概念,从异常检测的角度对蠕虫病毒采取了一种新型扼制方法。该方法的具体实施是建立完整的指数熵理论,推导出实用的熵值计算公式,结合局域网蠕虫病毒入侵检测技术,开发了高效的蠕虫病毒检测应用程序。实验结果表明,该方法可以检测到网络蠕虫,且具有较高的效率和较低的漏报率。
Based on the traditional theory of IDS, the system entropy is studied, which come from statistics model, combining the worm behaviors characteristic the exponent entropy conception is put forward, a new inhibiting method is proposed from the anomaly detection point of view. The concrete implementation of this method is build the integrity exponent entropy theory, deduced practical entropy value calculate formula, combined LAN worm IDS technology and developed worm detection applied program. The output of the program shows this method is feasible and has high efficiency.
出处
《计算机工程与设计》
CSCD
北大核心
2008年第24期6278-6280,共3页
Computer Engineering and Design
基金
陕西省教育厅基金项目(06JK231)
关键词
指数熵
蠕虫病毒
入侵检测
网络安全
检测算法
exponent entropy
worm
intrusion detection
web security
detection algorithm