DocumentCode :
3516165
Title :
Blue-Watchdog: Detecting Bluetooth worm propagation in public areas
Author :
Yan, Guanhua ; Cuellar, Leticia ; Eidenbenz, Stephan ; Hengartner, Nicolas
Author_Institution :
Los Alamos Nat. Lab., Los Alamos, NM, USA
fYear :
2009
fDate :
June 29 2009-July 2 2009
Firstpage :
317
Lastpage :
326
Abstract :
The rising popularity of mobile devices, such as cellular phones and PDAs, has made them a lucrative playground for mobile malware propagation. One common infection vector exploited by these mobile malware is Bluetooth. In this paper, we propose an architecture called Blue-Watchdog that detects Bluetooth worm propagation in public areas based on statistical methods. To achieve fast and accurate Bluetooth worm detection, Blue-Watchdog monitors abrupt changes of average paging rate per Bluetooth device from both temporal and temporal-spatial perspectives. The temporal scheme relies on the CUSUM (Cumulative Sum) sequential test together with the generalized likelihood ratio (GLR), and the temporal-spatial scheme aims to identify spatial regions with abnormally frequent paging attempts. Experimental results show that Blue-Watchdog not only has low false alarm rates, but also effectively detects Bluetooth worms that spread quickly in areas where Bluetooth devices are greatly mixed due to high mobility and also those that propagate relatively slowly in a spatially constrained fashion.
Keywords :
Bluetooth; invasive software; mobile radio; statistical analysis; telecommunication security; blue-watchdog architecture; bluetooth worm propagation detection; cumulative sum function; generalized likelihood ratio; mobile device; mobile malware propagation; statistical methods; temporal-spatial perspective; Bluetooth; Cellular phones; Computer worms; IP networks; Information security; Laboratories; Mathematical model; Personal digital assistants; Sequential analysis; Statistical analysis; Bluetooth; Bluetooth worms; CUSUM; temporal detection; temporal-spatial detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
Conference_Location :
Lisbon
Print_ISBN :
978-1-4244-4422-9
Electronic_ISBN :
978-1-4244-4421-2
Type :
conf
DOI :
10.1109/DSN.2009.5270319
Filename :
5270319
Link To Document :
بازگشت