首页> 外文OA文献 >A Pseudo-Worm Daemon (PWD) for empirical analysis of zero-day network worms and countermeasure testing
【2h】

A Pseudo-Worm Daemon (PWD) for empirical analysis of zero-day network worms and countermeasure testing

机译:用于零日网络蠕虫的经验分析和对策测试的伪蠕虫守护程序(PWD)

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The cyber epidemiological analysis of computer worms has emerged a key area of research in the field of cyber security. In order to understand the epidemiology of computer worms; a network daemon is required to empirically observe their infection and propagation behavior. The same facility can also be employed in testing candidate worm countermeasures. In this paper, we present the architecture and design of Pseudo-Worm Daemon; termed (PWD), which is designed to perform true random scanning and hit-list worm like functionality. The PWD is implemented as a proof-of-concept in C programming language. The PWD is platform independent and can be deployed on any host in an enterprise network. The novelty of this worm daemon includes; its UDP based propagation, a user-configurable random scanning pool, ability to contain a user defined hit-list, authentication before infecting susceptible hosts and efficient logging of time of infection. Furthermore, this paper presents experimentation and analysis of a Pseudo-Witty worm by employing the PWD with real Witty worm outbreak attributes. The results obtained by Pseudo-Witty worm outbreak are quite comparable to real Witty worm outbreak; which are further quantified by using the Susceptible Infected (SI) model.
机译:计算机蠕虫的网络流行病学分析已成为网络安全领域研究的关键领域。为了了解计算机蠕虫的流行病学;需要网络守护程序以凭经验观察其感染和传播行为。同样的设施也可以用于测试候选蠕虫对策。在本文中,我们介绍了伪蠕虫守护程序的体系结构和设计。称为(PWD),旨在执行真正的随机扫描和类似命中列表蠕虫的功能。 PWD是用C编程语言实现的概念证明。 PWD是独立于平台的,可以部署在企业网络中的任何主机上。该蠕虫守护程序的新颖性包括:其基于UDP的传播,用户可配置的随机扫描池,包含用户定义的命中列表,在感染易受感染主机之前进行身份验证以及有效记录感染时间的能力。此外,本文还介绍了通过使用具有真实Witty蠕虫爆发属性的PWD对伪Witty蠕虫进行的实验和分析。伪Witty蠕虫爆发获得的结果与真实的Witty蠕虫爆发相当。通过使用易感性感染(SI)模型进一步量化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号