【24h】

Paradigmatic and Exploration of Blind Worm

机译:盲虫的范式与探索

获取原文
           

摘要

Active worms pose major security threats to the Internet. This is due to the ability of active worms to propagate in an automated fashion as they continuously compromise computers on the Internet. Active worms evolve during their propagation and thus pose great challenges to defend against them. In this paper, we investigate a new class of active worms, referred to as TarnenWorm (C-Worm in short). The C-Worm is different from traditional worms because of its ability to intelligently manipulate its scan traffic volume over time. Thereby, the C-Worm camouflages its propagation from existing worm explorationsystems based on analyzing the propagation traffic generated by worms. We analyze characteristics of theC-Worm and conduct a comprehensive comparison between its traffic and non-worm traffic (background traffic). We observe that these two types of traffic are barely distinguishable in the time domain. However, their distinction is clear in the frequency domain, due to the recurring manipulative nature of the C-Worm. Motivated by our observations, we design a novel spectrum-based scheme to detect the C-Worm. Our scheme uses the Power Spectral Density (PSD) distribution of the scan traffic volume and its corresponding Spectral Flatness Measure (SFM) to distinguish the C-Worm traffic from background traffic. Using a comprehensive set of explorationmetric s and real-world traces as background traffic, we conduct extensive performance evaluations on our proposed spectrum-based explorationscheme. The performance data clearly demonstrates that our scheme can effectively detect the C-Worm propagation. Furthermore, we show the generality of our spectrum-based scheme in effectively detecting not only the C-Worm, but traditional worms as well.
机译:活动蠕虫对Internet构成主要的安全威胁。这是由于主动蠕虫在不断破坏Internet上的计算机时能够以自动方式传播。主动蠕虫在繁殖过程中会进化,因此对防御它们提出了巨大挑战。在本文中,我们研究了一种新型的活动蠕虫,称为TarnenWorm(简称C-Worm)。 C-蠕虫与传统蠕虫不同,因为它能够随着时间的推移智能地控制其扫描流量。因此,C-Worm在分析蠕虫产生的传播流量的基础上,掩盖了它从现有蠕虫探测系统中的传播。我们分析了C-蠕虫的特征,并对其流量和非蠕虫流量(背景流量)进行了全面比较。我们观察到,这两种流量在时域中几乎无法区分。但是,由于C型蠕虫的反复操纵性,它们的区别在频域中很明显。根据我们的观察结果,我们设计了一种基于频谱的新颖方案来检测C-蠕虫。我们的方案使用扫描流量的功率频谱密度(PSD)分布及其相应的频谱平坦度度量(SFM)来区分C蠕虫流量和背景流量。我们使用一套全面的勘探指标和真实世界的踪迹作为背景流量,我们对我们提出的基于频谱的勘探方案进行了广泛的性能评估。性能数据清楚地表明,我们的方案可以有效地检测C-蠕虫传播。此外,我们展示了基于频谱的方案的通用性,它不仅可以有效地检测C蠕虫,还可以有效地检测传统蠕虫。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号