首页> 外文会议>International Conference on Security and Privacy in Communication Networks and Workshops >PWC: A Proactive Worm Containment Solution for Enterprise Networks
【24h】

PWC: A Proactive Worm Containment Solution for Enterprise Networks

机译:PWC:企业网络的主动蠕虫遏制解决方案

获取原文

摘要

We propose PWC, a proactive worm containment solution for enterprises. PWC can stop - instead of slowing down - an infected host from releasing worm scans as early as after merely 4 scans. Motivated by the observation that a worm uses a sustained outgoing packet rate, PWC gains infection awareness seconds before a signature or filter can be generated. To overcome denial-of-service possibly caused by such smoking signs of infection, PWC develops two new white detection (detecting who are uninfected) techniques: (a) the vulnerability time window lemma, and (b) the relaxation analysis. PWC is signature-free thus it is immunized from polymorphic worms and timely in containing. PWC is also resilient to containment evading. PWC is not sensitive to worm scan rate, and not protocol specific. Due to white detection, PWC causes minimal denial-of-service. Evaluation based on real traces and worm simulations demonstrates that PWC significantly outperforms Virus Throttle [1] in terms of number of released worm scans, number of hosts infected by local scans, and availability.
机译:我们为企业提出了PWC,提供了一种积极的蠕虫遏制解决方案。 PWC可以停止 - 而不是放慢速度 - 早期4个扫描之后,从释放蠕虫扫描的感染宿主。通过观察到蠕虫使用持续的传出分组率,PWC可以在产生签名或滤波器之前获得感染感染秒。为了克服可能由这种吸烟迹象引起的拒绝服务,PWC开发了两种新的白色检测(检测谁是未感染的)技术:(a)漏洞时间窗引理,(b)放松分析。 PWC是无签名的,因此它被多态蠕虫免疫,及时含有。普华永道也适合遏制。 PWC对蠕虫扫描速率不敏感,而不是特定于协议。由于白色检测,PWC导致最小的拒绝服务。基于真实迹线和蠕虫模拟的评估表明,在释放的蠕虫扫描的数量方面,PWC显着优于病毒油门[1],当地扫描感染的宿主数量和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号