首页> 外文会议>IEEE International Conference on Computer Communications >Design and Evaluation of a Fast and Robust Worm Detection Algorithm
【24h】

Design and Evaluation of a Fast and Robust Worm Detection Algorithm

机译:快速耐用蠕虫检测算法的设计与评估

获取原文

摘要

Fast spreading worms are a reality, as amply demonstrated by worms such as Slammer, which reached its peak propagation in a matter of minutes. With these kinds of fast spreading worms, the traditional approach of signature-based detection is no longer sufficient. Specifically, these worms can infect all vulnerable hosts well before a signature is available. To counter them, we must devise fast detection algorithms that can detect new worms without signatures as they first begin to appear. We present the design and evaluation of such an algorithm in this paper. The key to the algorithm is the identification of certain invariant characteristics of worm propagation. Specifically, we are able to demonstrate using real network traces how worm propagation can perturb the arrival process distribution of unsolicited packets. Our algorithm employs a novel two-step procedure that combines a first stage change point detection with a second stage growth rate inference to confirm the existence of a worm. To evaluate the algorithm, we have applied it to multi-year network traces that cover many of the major worm outbreaks in recent years, including Slammer, Witty, Nimda and Blaster. In all cases, the new algorithm is able to detect the worm within a very short time, well before significant infection has taken place.
机译:快速蔓延的蠕虫是现实的,如潜在者如潜在者所展示的,这在几分钟内达到了峰值传播。通过这些类型的快速蔓延蠕虫,传统的基于签名的检测方法不再足够了。具体而言,在签名可用之前,这些蠕虫可以发出良好的弱势主机。为了衡量它们,我们必须设计快速检测算法,可以在没有签名的情况下检测新蠕虫,因为它们首次开始出现。我们在本文中提出了这种算法的设计和评估。算法的关键是识别蠕虫传播的某些不变特征。具体来说,我们能够使用真正的网络迹象来演示蠕虫传播如何扰乱到达过程分布的未经请求的数据包。我们的算法采用了一种新的两步步骤,它将第一级变化点检测与第二阶段的生长速率推断相结合,以确认蠕虫的存在。为了评估算法,我们已将其应用于多年网络迹线,近年来涵盖了许多主要的蠕虫爆发,包括砰砰行,诙谐,尼姆达和闪贷。在所有情况下,新算法能够在很短的时间内检测蠕虫,在显着感染发生之前。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号