• DocumentCode
    2870762
  • Title

    Host behaviour based early detection of worm outbreaks in Internet backbones

  • Author

    Diibendorfer, T. ; Plattner, Bernhard

  • Author_Institution
    Comput. Eng. & Networks Lab. (TIK), Swiss Fed. Inst. of Technol., Zurich, Switzerland
  • fYear
    2005
  • fDate
    13-15 June 2005
  • Firstpage
    166
  • Lastpage
    171
  • Abstract
    We propose a novel near real-time method for early detection of worm outbreaks in high-speed Internet backbones. Our method attributes several behavioural properties to individual hosts like ratio of outgoing to incoming traffic, responsiveness and number of connections. These properties are used to group hosts into distinct behaviour classes. We use flow-level (Cisco Net Flow) information exported by the border routers of a Swiss Internet backbone provider (AS559/SWITCH). By tracking the cardinality of each class over time and alarming on fast increases and other significant changes, we can early and reliably detect worm outbreaks. We successfully validated our method with archived flow-level traces of recent major Internet e-mail based worms such as MyDoomA and Sobig.F, and fast spreading network worms like Witty and Blaster. Our method is generic in the sense that it does not require any previous knowledge about the exploits and scanning method used by the worms. It can give a set of suspicious hosts in near real-time that have recently and drastically changed their network behaviour and hence are highly likely to be infected.
  • Keywords
    Internet; electronic mail; invasive software; telecommunication security; Blaster; Cisco Net Flow; Internet e-mail; MyDoomA; Sobig.F; Swiss Internet backbone provider; Witty; worm outbreak detection; Computer worms; Delay; Electronic mail; IP networks; Internet; Intrusion detection; Monitoring; Spine; Switches; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enabling Technologies: Infrastructure for Collaborative Enterprise, 2005. 14th IEEE International Workshops on
  • ISSN
    1524-4547
  • Print_ISBN
    0-7695-2362-5
  • Type

    conf

  • DOI
    10.1109/WETICE.2005.40
  • Filename
    1566204