%0 Journal Article %T Detecting worms based on candidate combination frequent pattern in Internet backbones
基于候选组合频繁模式的骨干网蠕虫检测研究 %A XU Xiao-dong %A YANG Su %A ZHU Shi-rui %A
许晓东 %A 杨甦 %A 朱士瑞 %J 计算机应用 %D 2009 %I %X The present worm detection methods have been mostly based on packets and less with IP flows in Internet backbones. They also cannot accurately describe the worm's scan-pattern. A method was presented to detect worms in Internet Backbones with flow data circumstance. First, find suspicious hosts by checking the increasing coefficients of Flow Activity Degree and Destination IP Address. Then, detect worms based on Candidate Combination Frequent Pattern Mining (CCFPM) algorithm. The results show that this meth... %K Worm attack detection %K IP Flows %K Candidate Combination Frequent Pattern Mining %K FP-Tree
蠕虫攻击检测 %K IP流 %K 候选组合频繁模式挖掘 %K FP-树 %U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=831E194C147C78FAAFCC50BC7ADD1732&aid=06E3BC00DDC992632A6B3E955F5F11DC&yid=DE12191FBD62783C&vid=771469D9D58C34FF&iid=CA4FD0336C81A37A&sid=4609832E4B5C797B&eid=F1A8654ADB4E656E&journal_id=1001-9081&journal_name=计算机应用&referenced_num=0&reference_num=13