首页> 外文期刊>Computers & Security >Worm virulence estimation for the containment of local worm outbreak
【24h】

Worm virulence estimation for the containment of local worm outbreak

机译:估计当地蠕虫爆发的蠕虫毒力

获取原文
获取原文并翻译 | 示例

摘要

A worm-infected host scanning globally may not cause any new infection in its underlying local network before it is detected and quarantined by a worm detector. To defend this type of scanning hosts, a number of worm scanner detection methods such as failed scan detection, honeypot, and dark port detection are proposed. However, for a stealthier worm limiting its scan inside an enterprise network, the chance of a successful local outbreak increases substantively due to the more limited scan space.rnTo protect a local or enterprise network against a local outbreak, we need a coordinated and cost-conscious defense that entails an accurate estimate of worm virulence level. Unfortunately, many existing defense methods suffer from estimating the worm virulence level in a local or enterprise network. In this regard, we propose a maximum likelihood estimator to progressively estimate the size of susceptible host population in the local or enterprise network. From analysis and experimental evaluation, it is shown that the proposed estimator can report a reliable estimate of the size of susceptible population only after a few infections, sometimes only four, much faster than a similar method based on a Kalman filter. Also, based on maximum likelihood estimate, an appropriate containment threshold can be set to effectively stop the worm propagation while causing minimum service disruption to normal network users.
机译:在蠕虫检测器检测到并隔离之前,全局扫描受蠕虫感染的主机可能不会在其基础局域网中引起任何新的感染。为了防御这种类型的扫描主机,提出了多种蠕虫扫描仪检测方法,例如扫描失败检测,蜜罐检测和暗端口检测。但是,对于更隐蔽的蠕虫,将其扫描限制在企业网络内部,由于扫描空间更有限,因此成功爆发本地病毒的机会显着增加。为了保护局域网或企业网络免受本地病毒爆发的侵扰,我们需要协调且成本合理的有意识的防御,需要准确估算蠕虫的毒力水平。不幸的是,许多现有的防御方法都难以估计本地或企业网络中的蠕虫病毒级别。在这方面,我们提出了一种最大似然估计器,以逐步估计本地或企业网络中易受感染的主机群的大小。从分析和实验评估中可以看出,所提出的估计器仅在少数感染(有时只有四个)感染后才能报告对易感人群大小的可靠估计,比基于卡尔曼滤波器的类似方法要快得多。另外,基于最大似然估计,可以设置适当的包含阈值,以有效阻止蠕虫传播,同时对正常网络用户造成最少的服务中断。

著录项

  • 来源
    《Computers & Security》 |2010年第1期|104-123|共20页
  • 作者单位

    Computer Science and Engineering Department, College of Information Sciences & Technology, Pennsylvania State University, University Park, PA 16802, USA;

    Institute of Microelectronics of Chinese Academy of Sciences, Beijing 100029, China;

    Computer Science and Engineering Department, College of Information Sciences & Technology, Pennsylvania State University, University Park, PA 16802, USA;

    Computer Science and Engineering Department, College of Information Sciences & Technology, Pennsylvania State University, University Park, PA 16802, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    global scanning worms; local scanning worms; worm containment; worm virulence estimation; maximum likelihood estimation;

    机译:全局扫描蠕虫;本地扫描蠕虫;蠕虫遏制;蠕虫毒力估计;最大似然估计;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号