首页> 外文会议>International Symposium on Information, Computer, and Communications Security >An integrated approach to detection of fast and slow scanning worms
【24h】

An integrated approach to detection of fast and slow scanning worms

机译:检测快速慢速扫描蠕虫的综合方法

获取原文

摘要

The propagation speed of fast scanning worms and the stealthy nature of slow scanning worms present unique challenges to intrusion detection. Typically, techniques optimized for detection of fast scanning worms fail to detect slow scanning worms, and vice versa. In practice, there is interest in developing an integrated approach to detecting both classes of worms. In this paper, we propose and analyze a unique integrated detection approach capable of detecting and identifying traffic flow(s) responsible for simultaneous fast and slow scanning malicious worm attacks. The approach uses a combination of evidence from distributed host-based anomaly detectors, a self-adapting profiler and Bayesian inference from network heuristics to detect intrusion activity due to both fast and slow scanning worms. We assume that the extreme nature of fast scanning worm epidemics make them well suited for extreme value theory and use sample mean excess function to determine appropriate thresholds for detection ofsuch worms. Random scanning worm behavior is considered in analyzing the stochastic time intervals that affect behavior of the detection technique. Based on the analysis, a probability model for worm detection interval using the detection scheme was developed. Simulations are used to validate our assumptions and analysis.
机译:快速扫描蠕虫的传播速度和慢速扫描蠕虫的隐身性质对入侵检测具有独特的挑战。通常,针对快速扫描蠕虫进行优化的技术未能检测慢速扫描蠕虫,反之亦然。在实践中,有兴趣开发综合方法来检测两类蠕虫。在本文中,我们提出并分析了一种独特的综合检测方法,能够检测和识别负责同时快速和慢速扫描恶意蠕虫攻击的交通流量。该方法使用来自基于分布式宿主的异常探测器的证据组合,从网络启发式中自适应分析仪和贝叶斯推断,以检测由于快速和慢速扫描蠕虫而导致的入侵活动。我们假设快速扫描蠕虫流行病的极端性质使其适用于极值理论,并使用样本意味着多余的功能来确定用于检测OSUCH蠕虫的适当阈值。在分析影响检测技术行为的随机时间间隔时,考虑随机扫描蠕虫行为。基于分析,开发了使用检测方案的蠕虫检测间隔的概率模型。模拟用于验证我们的假设和分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号