Computer Engineering and Applications ›› 2013, Vol. 49 ›› Issue (7): 93-97.

Previous Articles     Next Articles

Peer behavior based proactive P2P worm detection

ZHU Hui, LI Weihua, SHI Haobin   

  1. School of Computer Science and Engineering, Northwestern Polytechnical University, Xi’an 710129, China
  • Online:2013-04-01 Published:2013-04-15

基于节点行为的主动P2P蠕虫检测

朱  晖,李伟华,史豪斌   

  1. 西北工业大学 计算机学院,西安 710129

Abstract: Proactive P2P worm propagation is a serious security threat to P2P network and Internet. By researching the peer behavior of propagating proactive P2P worm, this paper puts forward PBD(Peer Behavior based Detection) to detect proactive P2P worm. On this basis, it designs and implements a PPWDS(Proactive P2P Worm Detection System). This system adopts CUSUM algorithm to carry out real time monitoring to the outbound short link of P2P peers. Experiments show that PBD is an effective method of proactive P2P worm detect.

Key words: proactive Peer to Peer(P2P) worm, peer behavior, Cumulative Sum(CUSUM) algorithm, detect

摘要: 主动P2P蠕虫的传播会对P2P网络以及互联网的安全造成严重威胁。通过研究主动P2P蠕虫传播时节点行为,提出一种基于节点行为的主动P2P蠕虫检测方法PBD(Peer Behavior based Detection)。在此基础上设计和实现了一个主动P2P蠕虫检测系统PPWDS(Proactive P2P Worm Detection System),该系统采用CUSUM算法对P2P节点出站短连接进行实时监控。实验表明,PBD是检测主动P2P蠕虫的一种有效方法。

关键词: 主动点对点(P2P)蠕虫, 节点行为, 累积和(CUSUM)算法, 检测