提出了一种基于P2P的大规模分布式网络恶意代码检测模型,描述了系统各个部分的功能与实现。该模型利用改进的Rabin指纹算法实现了对恶意代码特征码的自动提取。提出了基于子序列指纹的分布式存储的信息融合策略,并在此基础上给出了分布式架构下的恶意代码检测算法。这种方法适用于大规模网络中的恶意代码的检测。
This paper proposes a distributed malcode detection model based on distributed hash table (DHT) protocol for P2P networks and describes the functions and implementation of each part. The model uses an improved Rabin fingerprint algorithm to automatically extract malcode signatures. It also proposes the strategy of information communion based on distributed storing of the fingerprints of substring, and on the basis of this, presents the algorithm of malcode detection under a distributed system. It is shown that this model can be applied to malcode detection in large scale networks.