• DocumentCode
    2670947
  • Title

    DoWitcher: Effective Worm Detection and Containment in the Internet Core

  • Author

    Ranjan, S. ; Shah, S. ; Nucci, A. ; Munafó, M. ; Cruz, R. ; Muthukrishnan, S.

  • Author_Institution
    Narus Inc., Mountain View
  • fYear
    2007
  • fDate
    6-12 May 2007
  • Firstpage
    2541
  • Lastpage
    2545
  • Abstract
    Enterprise networks are increasingly offloading the responsibility for worm detection and containment to the carrier networks. However, current approaches to the zero-day worm detection problem such as those based on content similarity of packet payloads are not scalable to the carrier link speeds (OC-48 and up-wards). In this paper, we introduce a new system, namely DoWitcher, which in contrast to previous approaches is scalable as well as able to detect the stealthiest worms that employ low-propagation rates or polymorphisms to evade detection. DoWitcher uses an incremental approach toward worm detection: First, it examines the layer-4 traffic features to discern the presence of a worm anomaly; Next, it determines a flow-filter mask that can be applied to isolate the suspect worm flows and; Finally, it enables full-packet capture of only those flows that match the mask, which are then processed by a longest common subsequence algorithm to extract the worm content signature. Via a proof-of-concept implementation on a commercially available network analyzer processing raw packets from an OC-48 link, we demonstrate the capability of DoWitcher to detect low-rate worms and extract signatures for even the polymorphic worms.
  • Keywords
    Internet; computer viruses; telecommunication security; telecommunication traffic; DoWitcher; Internet core; flow-filter mask; full-packet capture; layer-4 traffic; longest common subsequence algorithm; network analyzer; polymorphic worms; polymorphisms; proof-of-concept implementation; worm anomaly; worm containment; worm content signature; worm detection; Communications Society; Computer networks; Computer worms; Gain control; IP networks; Internet; Intrusion detection; Payloads; Telecommunication traffic; USA Councils;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2007. 26th IEEE International Conference on Computer Communications. IEEE
  • Conference_Location
    Anchorage, AK
  • ISSN
    0743-166X
  • Print_ISBN
    1-4244-1047-9
  • Type

    conf

  • DOI
    10.1109/INFCOM.2007.317
  • Filename
    4215899