首页> 外文会议>ACM workshop on Rapid malcode >Simulating realistic network worm traffic for worm warning system design and testing
【24h】

Simulating realistic network worm traffic for worm warning system design and testing

机译:模拟现实的网络蠕虫流量,以进行蠕虫预警系统的设计和测试

获取原文

摘要

Reproducing the effects of large-scale worm attacks in a laboratory setup in a realistic and reproducible manner is an important issue for the development of worm detection and defense systems. In this paper, we describe a worm simulation model we are developing to accurately model the large-scale spread dynamics of a worm and many aspects of its detailed effects on the network. We can model slow or fast worms with realistic scan rates on realistic IP address spaces and selectively model local detailed network behavior. We show how it can be used to generate realistic input traffic for a working prototype worm detection and tracking system, the Dartmouth ICMP BCC: System/Tracking and Fusion Engine (DIB:S/TRAFEN), allowing performance evaluation of the system under realistic conditions. Thus, we can answer important design questions relating to necessary detector coverage and noise filtering without deploying and operating a full system. Our experiments indicate that the tracking algorithms currently implemented in the DIB:S/TRAFEN system could detect attacks such as Code Red v2 and Sapphire/Slammer very early, even when monitoring a quite limited portion of the address space, but more sophisticated algorithms are being constructed to reduce the risk of false positives in the presence of significant "background noise" scanning.
机译:在实验室设置中以现实且可复制的方式再现大规模蠕虫攻击的影响,是开发蠕虫检测和防御系统的重要问题。在本文中,我们描述了一种蠕虫仿真模型,该模型正在开发中,可以准确地对蠕虫的大规模传播动力学及其对网络的详细影响的许多方面进行建模。我们可以在真实的IP地址空间上以真实的扫描速率对慢速蠕虫或快速蠕虫进行建模,并选择性地对本地详细的网络行为进行建模。我们展示了如何将其用于为有效的原型蠕虫检测和跟踪系统Dartmouth ICMP BCC:系统/跟踪和融合引擎(DIB:S / TRAFEN)生成现实的输入流量,从而在现实条件下对系统进行性能评估。因此,我们可以在不部署和运行整个系统的情况下回答与必要的检测器覆盖范围和噪声过滤有关的重要设计问题。我们的实验表明,即使在监视地址空间中相当有限的部分时,DIB:S / TRAFEN系统中当前实现的跟踪算法也可以很早地检测到诸如Red Red v2和Sapphire / Slammer之类的攻击。为了减少在出现明显的“背景噪声”扫描时出现误报的风险而设计的扫描仪。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号