提出了基于拓扑结构控制的蠕虫防御策略,并通过构建仿真模型对其进行了仿真验证分析.首先对蠕虫传播所依赖的拓扑结构的主要形式进行了分析,提出了相应的生成算法,并对算法的有效性进行了验证;随后提出了三种拓扑结构控制策略仿真模型;最后分别对这三种策略在不同拓扑结构下的蠕虫传播控制性能进行了仿真实验.实验结果证明:通过适当地控制拓扑结构,可以有效地遏制拓扑相关蠕虫传播.
Topology aware worms have been an important security threat on the Internet. They can spread across the Internet quickly, through topology structure information. If the topology structure were destroyed by defense strategies, the worm propagation can be held back effectively. Thus, in order to design effective topology aware worm defense strategies, it is necessary to analyze the relationship between worm defense strategies and topology structure. This paper provides a systemic analysis of worm defense strategies based on topology structure through packet level worm simulation. First the major topology structures used by topology aware worms and their generation algorithms are analyzed. Then, three defense strategy models are drawn from mainstream worm defense strategies. Finally, these defense strategies in different topology structure are analyzed with simulation experiments, and some interesting conclusions are drawn from these experiment results. These conclusions can provide valuable guidelines for real defense system implementation.