• DocumentCode
    2274142
  • Title

    Worm detection, early warning and response based on local victim information

  • Author

    Gu, Guofei ; Sharif, Monirul ; Qin, Xinzhou ; Dagon, David ; Lee, Wenke ; Riley, George

  • Author_Institution
    Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2004
  • fDate
    6-10 Dec. 2004
  • Firstpage
    136
  • Lastpage
    145
  • Abstract
    Worm detection systems have traditionally focused on global strategies. In the absence of a global worm detection system, we examine the effectiveness of local worm detection and response strategies. This paper makes three contributions: (1) we propose a simple two-phase local worm victim detection algorithm, DSC (Destination-Source Correlation), based on worm behavior in terms of both infection pattern and scanning pattern. DSC can detect zero-day scanning worms with a high detection rate and very low false positive rate. (2) We demonstrate the effectiveness of early worm warning based on local victim information. For example, warning occurs with 0.19% infection of all vulnerable hosts on Internet when using a /12 monitored network. (3) Based on local victim information, we investigate and evaluate the effectiveness of an automatic real-time local response in terms of slowing down the global Internet worms propagation. (2) and (3) are general results, not specific to certain detection algorithm like DSC. We demonstrate (2) and (3) with both analytical models and packet-level network simulator experiments.
  • Keywords
    Internet; invasive software; monitoring; real-time systems; Destination-Source Correlation algorithm; global Internet worms propagation; global worm detection system; local victim information; packet-level network simulator; two-phase local worm victim detection algorithm; Analytical models; Computer crime; Computer worms; Computerized monitoring; Condition monitoring; Detection algorithms; IP networks; Internet; Intrusion detection; Probes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2004. 20th Annual
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-2252-1
  • Type

    conf

  • DOI
    10.1109/CSAC.2004.51
  • Filename
    1377224