Worm detection technology research of net-flow dynamic critical line established based on statistical analytic method

王勇超,谢永凯,朱之平,林怀忠
DOI: https://doi.org/10.3969/j.issn.1001-3695.2010.03.062
2010-01-01
Abstract:This paper raised a method detect the abnormal net-flow based on normal distribution,then estimated the existence of Internet worm in internal network.According to the normal distribution character of the history flow,this method computed the normal behavior trusted zone of data flow in network,judged the inspected flow abnormal flow if it went beyond the trusted zone,and alarmed the threat of Internet worm.Combined with this method,further analyzed how to use two-factor model ana-lysis of the number of Internet worms in network.
What problem does this paper attempt to address?