Title :
Dynamic control of worm propagation
Author :
Dantu, Ram ; Cangussu, João ; Yelimeli, Arun
Author_Institution :
North Texas Univ., Denton, TX, USA
Abstract :
In a computer network, network security is accomplished using elements like firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm in priori to detect the attack. Modern day viruses like Code red, Sapphire and Nimda spread very fast. For example, Sapphire can double its size and infect more than 90% of the vulnerable hosts within 10 minutes. Therefore it is impractical if not impossible for human mediated responses to these modern day fast spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control is an effective method in containing the damage. In this paper we propose a state space feedback control model to detect and control the spread of these viruses by measuring the number of connections an infected host makes. The objective of the mechanism is to slow down the spreading velocity of a worm by controlling (delaying) the total number of connections made by an infected host. As expected, the model showed that the sooner the infection is detected the faster the reduction of the spreading velocity. Additionally, the deployment of a controller at different levels (host and firewall) has shown to be very promising.
Keywords :
authorisation; computer networks; feedback; invasive software; system monitoring; telecommunication security; Code red; Nimda; Sapphire; attack detection; automatic tracking; computer network; computer viruses; dynamic control; firewalls; infected host; intrusion detection systems; network elements; network security; resource usage; routers; servers; spreading velocity; state space feedback control model; worm propagation; Automatic control; Computer networks; Computer security; Computer viruses; Computer worms; Humans; Intrusion detection; Network servers; State-space methods; Viruses (medical);
Conference_Titel :
Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
Print_ISBN :
0-7695-2108-8
DOI :
10.1109/ITCC.2004.1286491