• DocumentCode
    3516165
  • Title

    Blue-Watchdog: Detecting Bluetooth worm propagation in public areas

  • Author

    Yan, Guanhua ; Cuellar, Leticia ; Eidenbenz, Stephan ; Hengartner, Nicolas

  • Author_Institution
    Los Alamos Nat. Lab., Los Alamos, NM, USA
  • fYear
    2009
  • fDate
    June 29 2009-July 2 2009
  • Firstpage
    317
  • Lastpage
    326
  • Abstract
    The rising popularity of mobile devices, such as cellular phones and PDAs, has made them a lucrative playground for mobile malware propagation. One common infection vector exploited by these mobile malware is Bluetooth. In this paper, we propose an architecture called Blue-Watchdog that detects Bluetooth worm propagation in public areas based on statistical methods. To achieve fast and accurate Bluetooth worm detection, Blue-Watchdog monitors abrupt changes of average paging rate per Bluetooth device from both temporal and temporal-spatial perspectives. The temporal scheme relies on the CUSUM (Cumulative Sum) sequential test together with the generalized likelihood ratio (GLR), and the temporal-spatial scheme aims to identify spatial regions with abnormally frequent paging attempts. Experimental results show that Blue-Watchdog not only has low false alarm rates, but also effectively detects Bluetooth worms that spread quickly in areas where Bluetooth devices are greatly mixed due to high mobility and also those that propagate relatively slowly in a spatially constrained fashion.
  • Keywords
    Bluetooth; invasive software; mobile radio; statistical analysis; telecommunication security; blue-watchdog architecture; bluetooth worm propagation detection; cumulative sum function; generalized likelihood ratio; mobile device; mobile malware propagation; statistical methods; temporal-spatial perspective; Bluetooth; Cellular phones; Computer worms; IP networks; Information security; Laboratories; Mathematical model; Personal digital assistants; Sequential analysis; Statistical analysis; Bluetooth; Bluetooth worms; CUSUM; temporal detection; temporal-spatial detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
  • Conference_Location
    Lisbon
  • Print_ISBN
    978-1-4244-4422-9
  • Electronic_ISBN
    978-1-4244-4421-2
  • Type

    conf

  • DOI
    10.1109/DSN.2009.5270319
  • Filename
    5270319