DocumentCode :
2312195
Title :
Understanding Divide-Conquer-Scanning Worms
Author :
Li, Yubin ; Chen, Zesheng ; Chen, Chao
Author_Institution :
Dept. of Electr.&Comput. Eng., Florida Int. Univ., Miami, FL
fYear :
2008
fDate :
7-9 Dec. 2008
Firstpage :
51
Lastpage :
58
Abstract :
Internet worms have been a significant security threat. Divide-conquer scanning is a simple yet effective technique that can potentially be exploited by future Internet epidemics. Therefore, it is imperative that defenders understand the characteristics of divide-conquer-scanning worms and study the countermeasures. In this work, we first provide the intuitions that a divide-conquer-scanning worm can potentially spread faster and stealthier than a traditional random-scanning worm. We then characterize the relationships between the propagation speeds of divide-conquer-scanning worms and the distributions of vulnerable hosts through mathematical analysis and simulations. Specifically, we find that if vulnerable hosts follow a non-uniform distribution such as the Witty-worm victim distribution, divide-conquer scanning can spread a worm much faster than random scanning. We also study empirically the effect of important parameters on the spread of divide-conquer-scanning worms. Furthermore, to counteract such attacks, we discuss the weakness of divide-conquer scanning and study a defense mechanism.
Keywords :
Internet; invasive software; Internet epidemics; Internet worms; divide-conquer-scanning worms; mathematical analysis; Analytical models; Chaos; Computer security; Computer worms; Electronic mail; Internet; Mathematical analysis; Partitioning algorithms; Probes; Space exploration;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
Conference_Location :
Austin, Texas
ISSN :
1097-2641
Print_ISBN :
978-1-4244-3368-1
Electronic_ISBN :
1097-2641
Type :
conf
DOI :
10.1109/PCCC.2008.4745139
Filename :
4745139
Link To Document :
بازگشت