首页> 外文期刊>Operating systems review >Vigilante: End-to-End Containment of Internet Worms
【24h】

Vigilante: End-to-End Containment of Internet Worms

机译:治安:互联网蠕虫的端到端遏制

获取原文
获取原文并翻译 | 示例
           

摘要

Worm containment must be automatic because worms can spread too fast for humans to respond. Recent work has proposed network-level techniques to automate worm containment; these techniques have limitations because there is no information about the vulnerabilities exploited by worms at the network level. We propose Vigilante, a new end-to-end approach to contain worms automatically that addresses these limitations. Vigilante relies on collaborative worm detection at end hosts, but does not require hosts to trust each other. Hosts run instrumented software to detect worms and broadcast self-certifying alerts (SCAs) upon worm detection. SCAs are proofs of vulnerability that can be inexpensively verified by any vulnerable host. When hosts receive an SCA, they generate filters that block infection by analysing the SCA-guided execution of the vulnerable software. We show that Vigilante can automatically contain fast-spreading worms that exploit unknown vulnerabilities without blocking innocuous traffic.
机译:蠕虫的遏制必须是自动的,因为蠕虫的传播速度太快,人类无法做出响应。最近的工作提出了网络级技术来自动控制蠕虫。这些技术有局限性,因为没有关于蠕虫在网络级别利用的漏洞的信息。我们建议使用Vigilante,这是一种新的端到端方法,可以自动包含蠕虫,从而解决了这些限制。 Vigilante依赖于最终主机上的协作蠕虫检测,但不需要主机相互信任。主机运行检测到的软件来检测蠕虫,并在检测到蠕虫时广播自认证警报(SCA)。 SCA是脆弱性的证明,任何脆弱的主机都可以廉价地对其进行验证。当主机收到SCA时,它们会通过分析SCA指导的易受攻击软件的执行来生成阻止感染的筛选器。我们表明,Vigilante可以自动包含利用未知漏洞而不会阻止无害流量的快速传播的蠕虫。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号