标题: 一个针对电脑蠕虫防治的混合侦测演算法
A hybrid algorithm for detecting computer worms
作者: 陈英裕
Ying-Yu Chen
罗济群
Chi-Chun Lo
管理学院资讯管理学程
关键字: 电脑蠕虫;负面表列;正面表列;平行比对;决策树模型;WMI;Computer Worms;Negative form;Positive form;Parallel ratio Method;Decision Tree Model;WMI
公开日期: 2007
摘要: 近年来,一些在电脑网路上散布流传的电脑病毒(Computer Viruses)急剧增加,广义来说,电脑病毒指的是各式各样具有感染、复制、破坏或影响电脑正常运作的电脑程式。较早期的电脑病毒必须靠档案交换才能感染,电脑感染后通常会有一定程度的破坏性,例如:无法开机、档案损毁、出现错误讯息、耗用系统资源等。其形式可分为开机型病毒(Boot Viruses)、Windows病毒(Windows Viruses)、JAVA/ActiveX病毒(Java/ActiveX Viruses)、指令档型病毒(Script Viruses)、巨集型病毒等(Macro Viruses)。

有别于早期的电脑病毒,近年来较为流行的电脑病毒透过较为先进的感染手法以感染网路上其他电脑,其形式可分为电脑蠕虫(Computer Worm)、特洛依木马程式(Trojans Horse Programs)、PE型程式、间谍程式(Spyware)、及后门程式(Backdoors Programs)等,相较于早期的电脑病毒,这些型态的电脑病毒对于电脑安全的影响与威胁是急剧增加的。

由于目前普遍使用的防毒软体(Anti-virus Software),其病毒码的产生、部署更新到完全清除电脑蠕虫,整个流程中仍存在着一定的时间差,本论文从电脑病毒的形成原因、特性描述、散布感染的途径、造成的影响与威胁与解决方案的探讨着手,进而聚焦于其中感染能力最强、传播数度最快的电脑蠕虫,透过负面表列清单并采取平行比对手法,搭配正面表列清单与决策树模型判断所形成之‘混合侦测演算法’,对其进行侦测与分析。

透过此混合侦测演算法,能够快速侦测出系统异常的状况,分析时也能够快速定义出电脑蠕虫的特性,并据此产生出一套简易的工具程式来协助网路管理者快速清除电脑蠕虫,够提大幅缩短等待病毒码更新的时间,提高作业系统的防护能力。
In recent years, some "Computer Viruses" of dispersal increases quickly on the network. Generally, computer viruses included various computer programs which have the ability to infection, replication and break or influence a computer‘s operate. Earlier computer viruses infection depends on file commutation, computer usually have the destructiveness of certain degree after infecting. For example: Can't boot, file damage, show error message and system resource overhead etc. Its form can be divided into these type: "Boot Viruses", "Windows Viruses", "Java/ActiveX Viruses", "Script Viruses", "Macro Viruses".
Different from traditional computer viruses, the near future computer viruses ascends other computers by infection network through advanced infection skill. Its form can be divided into "PE program", "Trojans Horse Programs", "Spyware", “Computer Worm" and "Backdoors Programs" etc. Compare with the earlier computer viruses, these types computer viruses influence toward computer security and threat are rapid to increase.
Currently the anti-virus software of widespread usage, the process of build virus pattern, deploy to computer and clear computer viruses still have time margin, this thesis begins the study of describe the become reason, characteristic, the way of spreads and infection, influence, threats and resolve solution of computer viruses. Then focused in to computer worms that with the best ability of infection and spread quickest. Through the “Hybrid Algorithm” by using “Negative form list“ and “Parallel ratio method” mixture with “Positive form list” and “Decision tree model” to detecting and analyzing computer worms.

Through “Hybrid Algorithm”, we can detect the system abnormality quickly, when we analyzing it, this method also can define the characteristic of computer worms and produce a set of simple tool to help network administrator to clear computer worms in a short time, reduce the time to wait for update anti-virus pattern and can raise the protection ability of the operation system.
URI: http://140.113.39.130/cdrfb3/record/nctu/#GT009164505
http://hdl.handle.net/11536/62546
显示于类别:Thesis