首页> 外文期刊>ACM transactions on autonomous and adaptive systems >A Host-Based Approach for Unknown Fast-Spreading Worm Detection and Containment
【24h】

A Host-Based Approach for Unknown Fast-Spreading Worm Detection and Containment

机译:基于主机的未知快速传播蠕虫检测和遏制方法

获取原文
获取原文并翻译 | 示例

摘要

The fast-spreading worm, which immediately propagates itself after a successful infection, is becoming one of the most serious threats to today's networked information systems. In this article, we present WormTer-minator, a host-based solution for fast Internet worm detection and containment with the assistance of virtual machine techniques based on the fast-worm denning characteristic. In WormTerminator, a virtual machine cloning the host OS runs in parallel to the host OS. Thus, the virtual machine has the same set of vulnerabilities as the host. Any outgoing traffic from the host is diverted through the virtual machine. If the outgoing traffic from the host is for fast worm propagation, the virtual machine should be infected and will exhibit worm propagation pattern very quickly because a fast-spreading worm will start to propagate as soon as it successfully infects a host. To prove the concept, we have implemented a prototype of WormTerminator and have examined its effectiveness against the real Internet worm Linux/Slapper. Our empirical results confirm that WormTerminator is able to completely contain worm propagation in real-time without blocking any non-worm traffic. The major performance cost of WormTerminator is a one-time delay to the start of each outgoing normal connection for worm detection. To reduce the performance overhead, caching is utilized, through which WormTerminator will delay no more than 6% normal outgoing traffic for such detection on average.
机译:快速传播的蠕虫在成功感染后立即传播,正在成为当今网络信息系统最严重的威胁之一。在本文中,我们介绍了WormTer-minator,这是一种基于主机的解决方案,可借助基于快速蠕虫识别特征的虚拟机技术,对Internet蠕虫进行快速检测和遏制。在WormTerminator中,克隆主机OS的虚拟机与主机OS并行运行。因此,虚拟机具有与主机相同的漏洞集。来自主机的所有传出流量都会通过虚拟机转移。如果来自主机的传出流量是用于蠕虫的快速传播,则虚拟机应被感染并很快呈现蠕虫传播模式,因为一旦快速感染蠕虫成功感染主机,它就会开始传播。为了证明这一概念,我们已经实现了WormTerminator的原型,并检查了其对真正的Internet蠕虫Linux / Slapper的有效性。我们的经验结果证实,WormTerminator能够实时完全遏制蠕虫传播,而不会阻塞任何非蠕虫流量。 WormTerminator的主要性能成本是每次蠕虫检测到每个传出正常连接的启动都存在一次延迟。为了减少性能开销,使用了缓存,通过该缓存,WormTerminator将平均延迟不超过6%的正常传出流量进行此类检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号