DocumentCode :
1266627
Title :
Self-Disciplinary Worms and Countermeasures: Modeling and Analysis
Author :
Yu, Wei ; Zhang, Nan ; Fu, Xinwen ; Zhao, Wei
Author_Institution :
Dept. of Comput. & Inf. Sci., Towson Univ., Towson, MD, USA
Volume :
21
Issue :
10
fYear :
2010
Firstpage :
1501
Lastpage :
1514
Abstract :
In this paper, we address issues related to the modeling, analysis, and countermeasures of worm attacks on the Internet. Most previous work assumed that a worm always propagates itself at the highest possible speed. Some newly developed worms (e.g., “Atak” worm) contradict this assumption by deliberately reducing the propagation speed in order to avoid detection. As such, we study a new class of worms, referred to as self-disciplinary worms. These worms adapt their propagation patterns in order to reduce the probability of detection, and eventually, to infect more computers. We demonstrate that existing worm detection schemes based on traffic volume and variance cannot effectively defend against these self-disciplinary worms. To develop proper countermeasures, we introduce a game-theoretic formulation to model the interaction between the worm propagator and the defender. We show that an effective integration of multiple countermeasure schemes (e.g., worm detection and forensics analysis) is critical for defending against self-disciplinary worms. We propose different integrated schemes for fighting different self-disciplinary worms, and evaluate their performance via real-world traffic data.
Keywords :
Internet; game theory; invasive software; Internet; detection probability; game theoretic formulation; self-disciplinary worms; worm detection schemes; worm propagation; Computer crime; Computer networks; Computer science; Computer security; Computer worms; Distributed computing; Forensics; Game theory; Traffic control; Web and internet services; Worm; anomaly detection.; game theory;
fLanguage :
English
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
Publisher :
ieee
ISSN :
1045-9219
Type :
jour
DOI :
10.1109/TPDS.2009.161
Filename :
5313807
Link To Document :
بازگشت