Network-based Malcode Detection Technology

WU Bing,YUN Xiao-chun,GAO Qi
DOI: https://doi.org/10.3321/j.issn:1000-436x.2007.11.014
2007-01-01
Abstract:Following the analysis for traditional distributed IDS,disadvantages that applying structure of multiple engine and small rules set to detect network-level malcode were pointed out,which is based on detailed protocol decoding.Detection model and anti-malcode markup language of network-level malcode were designed for single engine and big rules set.The characteristics of network data flow were analyzed.By optimization of patterns,frequent collisions between suffix with data flow and unbalanced branched of chained list were avoided.The efficiency by using WM algorithm to detect malcode on network level can be remarkably increased.
What problem does this paper attempt to address?