DocumentCode :
2966854
Title :
A framework for real-time worm attack detection and backbone monitoring
Author :
Dubendorfer, Thomas ; Wagner, Arno ; Plattner, Bernhard
Author_Institution :
Lab. of Comput. Eng. & Networks, Swiss Fed. Inst. of Technol., Zurich, Switzerland
fYear :
2005
fDate :
3-4 Nov. 2005
Abstract :
We developed an open source Internet backbone monitoring and traffic analysis framework named UPFrame. It captures UDP NetFlow packets, buffers it in shared memory and feeds it to customised plug-ins. UPFrame is highly tolerant to misbehaving plug-ins and provides a watchdog mechanism for restarting crashed plug-ins. This makes UP-Frame an ideal platform for experiments. It also features a traffic shaper for smoothing incoming traffic bursts. Using this framework, we have investigated IDS-like anomaly detection possibilities for high-speed Internet backbone networks. We have implemented several plug-ins for host behaviour classification, traffic activity pattern recognition, and traffic monitoring. We successfully detected the recent Blaster, Nachi and Witty worm outbreaks in a medium-sized Swiss Internet backbone (AS559) using border router NetFlow data captured in the DDoSVax project. The framework is efficient and robust and can complement traditional intrusion detection systems.
Keywords :
Internet; monitoring; telecommunication security; telecommunication traffic; Blaster outbreaks; Internet backbone monitoring; Nachi outbreaks; UDP NetFlow packets; UPFrame; Witty worm outbreaks; intrusion detection systems; medium-sized Swiss Internet backbone; real-time worm attack detection; traffic activity pattern recognition; traffic analysis; traffic monitoring; watchdog mechanism; Computer crashes; Feeds; IP networks; Internet; Monitoring; Pattern recognition; Robustness; Smoothing methods; Spine; Telecommunication traffic; Blaster; Nachi; NetFlow; UPFrame; Witty; anomaly detection; backbone; framework; host behaviour; online analysis; plug-in; worm outbreak;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Critical Infrastructure Protection, First IEEE International Workshop on
Print_ISBN :
0-7695-2426-5
Type :
conf
DOI :
10.1109/IWCIP.2005.2
Filename :
1572282
Link To Document :
بازگشت