Worm detection, early warning and response based on local victim information

ACSAC '04 Proceedings of the 20th Annual Computer Security Applications Conference(2004)

引用 166|浏览0
暂无评分
摘要
Worm detection systems have traditionally focused on global strategies. In the absence of a global worm detection system, we examine the effectiveness of local worm detection and response strategies. This paper makes three contributions: (1) we propose a simple two-phase local worm victim detection algorithm, DSC (Destination-Source Correlation), based on worm behavior in terms of both infection pattern and scanning pattern. DSC can detect zero-day scanning worms with a high detection rate and very low false positive rate. (2) We demonstrate the effectiveness of early worm warning based on local victim information. For example, warning occurs with 0.19% infection of all vulnerable hosts on Internet when using a /12 monitored network. (3) Based on local victim information, we investigate and evaluate the effectiveness of an automatic real-time local response in terms of slowing down the global Internet worms propagation. (2) and (3) are general results, not specific to certain detection algorithm like DSC. We demonstrate (2) and (3) with both analytical models and packet-level network simulator experiments.
更多
查看译文
关键词
simple two-phase local worm,destination-source correlation algorithm,invasive software,local victim information,victim detection algorithm,global worm detection system,worm detection,monitoring,global internet worms propagation,certain detection algorithm,internet,worm detection system,two-phase local worm victim detection algorithm,local worm detection,packet-level network simulator,worm behavior,high detection rate,early worm warning,real-time systems,false positive rate,real time,network simulator,early warning,real time systems
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要