...
【24h】

Paradigmatic and Exploration of Blind Worm

机译:盲虫的范式与探索

获取原文
           

摘要

Active worms pose major security threats to the Internet. This is due to the ability of active worms to propagate in an automated fashion as they continuously compromise computers on the Internet. Active wo rms evolve during their propagation and thus pose great challenges to defend against them. In this paper , we investigate a new class of active worms, referred to as Tarnen Worm (C Worm in short). The C Worm is different from traditional worms because of it s ability to intelligently manipulate its scan traffic volume over time. Thereby, the C Worm camouflages its propagation from existing worm exploration systems based on analyzing the propagation traffic generated by worms. We analyze characteristics of the C Worm and conduct a comprehensive comparison between its traf fic and non worm traffic (background traffic). We observe that these two types of traffic are barely distinguishable in the time domain. However, their distinction is cl ear in the frequency dom ain, due to the recurring manipulative nature of the C Worm. Motivated by our observations, we design a novel spectrum based scheme to detect the C Worm. Our scheme uses the Power Spectral Density (PSD) distribution of the scan traffic volume and its corre sponding Spectral Flatness Measure (SFM) to distinguish the C Worm traffic from background traf fic. Using a comprehensive set of exploration metric s and real world traces as background traffic, we conduct extensive pe rformance evaluations on our pr oposed spec trum based exploration scheme. Th e performance data clearly demonstrates that our scheme can effectively de tect the C Worm propagation. Fu rthermore, we show the generality of our spectrum based scheme in effectively detecting not only the C Worm, but t raditional worms as well
机译:活动蠕虫对Internet构成主要的安全威胁。这是由于主动蠕虫在不断破坏Internet上的计算机时能够以自动方式传播。活跃的蠕虫在传播过程中会进化,因此面临着严峻的挑战。在本文中,我们研究了一种新型的活动蠕虫,称为Tarnen蠕虫(简称C蠕虫)。 C蠕虫与传统蠕虫不同,因为它能够随时间智能地控制其扫描流量。因此,C蠕虫会在分析蠕虫产生的传播流量的基础上,掩盖其从现有蠕虫探测系统中的传播。我们分析了C蠕虫的特征,并对其流量和非蠕虫流量(背景流量)进行了全面比较。我们观察到,这两种流量在时域中几乎无法区分。但是,由于C蠕虫的反复操纵性,它们的区别在频率方面是显而易见的。根据我们的观察,我们设计了一种基于频谱的新颖方案来检测C蠕虫。我们的方案使用扫描流量的功率谱密度(PSD)分布及其相应的频谱平坦度测量(SFM)来区分C蠕虫流量与背景流量。使用一套全面的勘探指标和真实世界的痕迹作为背景流量,我们对基于光谱的勘探方案进行了广泛的性能评估。性能数据清楚地表明,我们的方案可以有效地检测C蠕虫传播。此外,我们展示了基于频谱的方案的通用性,不仅可以有效检测C蠕虫,还可以有效检测传统蠕虫

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号