Virus Detection System – the Architecture of and Approach to A Network Virus Detection System

Xinguang Xiao,Bing Wu,Xiaochun Yun,Yongliang Qiu
2012-01-01
Abstract:After detailed analysis of the structure of traditional IDS, we believe that it doesn’t work well on a high speed network with various viruses. What we need is accurate and high-speed detection of virus transmission and of the attacks of known viruses as well as as-yet-unkown viruses. Based on port mirroring and the normalization theory, we developed the algorithm efficiency oriented Virus Detection System (VDS). We implemented a mechanism which adapts to the bandwidth by adopting simple divergence, a parallel large sign set and high speed matching, and parallel protocol resolution. This paper presents the data processing method used by VDS by introducing the AVML and DEDL. Deep processing and unknown virus discovery are also introduced.
What problem does this paper attempt to address?