Title :
Worm Containment in Peer-to-Peer Networks
Author :
Yang, Sirui ; Jin, Hai ; Li, Bo ; Liao, Xiaofei ; Yao, Hong
Author_Institution :
Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
Abstract :
Recently there have been increasing attentions on the security aspects in Peer-to-Peer (P2P) networks, especially with respect to worm epidemics. However, existing worm containment mechanisms can be largely ineffective due to the long delay exhibited in worm identification and patch generation. In this paper, we propose a new worm containment algorithm based on the concept of overlay partition, which can effectively quarantine worms into small and more manageable sub-networks. This algorithm relies on a simple anomaly detection which takes effect much faster than existing schemes. With ldquobridge linksrdquo, the alert of an anomaly can be disseminated faster than random scanning and dedicated worms. Further, in order to deal with false positives, we propose a granularity based clustering algorithm, called CAGA, which, through extensive simulation, is shown to realize better service sustenance during unnecessary partition caused by false positives and can effectively contain fast worms. Finally, we examine the effects of topologies and network dynamics.
Keywords :
invasive software; pattern clustering; peer-to-peer computing; telecommunication network topology; telecommunication security; anomaly detection; granularity-based clustering algorithm; network topology; patch generation; peer-to-peer network; worm containment algorithm; worm epidemics; worm identification; worm quarantine; Clustering algorithms; Computer networks; Computer science; Computer security; Computer worms; Delay; Embedded computing; Grid computing; Partitioning algorithms; Peer to peer computing;
Conference_Titel :
Scalable Computing and Communications; Eighth International Conference on Embedded Computing, 2009. SCALCOM-EMBEDDEDCOM'09. International Conference on
Conference_Location :
Dalian
Print_ISBN :
978-0-7695-3825-9
DOI :
10.1109/EmbeddedCom-ScalCom.2009.62