分析了网络蠕虫的生命周期和传播模型,根据蠕虫的特性提出一种新的蠕虫检测方法,该方法首先监测网络上各主机的连接度,得到疑似感染蠕虫主机的数量.然后利用最小二乘法判别疑似感染蠕虫主机的数量变换是否符合蠕虫的传播模型.实验证明,该检测方法能够快速有效地检测出未知网络蠕虫的爆发.
The worm's behavior model and propagation model are presented. Then a new approach to early detection of Intemet worms is provided. The method can be divided into two parts: monitoring computers' connection degree in metwork and detecting Intemet worms using method of least squares. The experiment result proves that our approach is effectively and quickly to detect unknown worm.