• DocumentCode
    3516568
  • Title

    Verme: Worm containment in overlay networks

  • Author

    Freitas, Filipe ; Marques, Edgar ; Rodrigues, Rodrigo ; Ribeiro, Carlos ; Ferreira, Paulo ; Rodrigues, Luís

  • Author_Institution
    INESC-ID, Tech. Univ. of Lisbon, Lisbon, Portugal
  • fYear
    2009
  • fDate
    June 29 2009-July 2 2009
  • Firstpage
    155
  • Lastpage
    164
  • Abstract
    Topological worms, such as those that propagate by following links in an overlay network, have the potential to spread faster than traditional random scanning worms because they have knowledge of a subset of the overlay nodes, and choose these nodes to propagate themselves; and also because they can avoid traditional detection mechanisms. Furthermore, this worm propagation strategy is likely to become prevalent as the deployment of networks with a sparse address space, such as IPv6, makes the traditional random scanning strategy futile. We present a novel approach for containing topological worms based on the fact that some overlay nodes may not have common vulnerabilities, due to their platform diversity. By reorganizing the overlay graph, it is possible to contain topological worms in small islands of nodes with common vulnerabilities that only have knowledge of themselves or nodes running on distinct platforms. We also present the design of Verme, a peer-to-peer overlay based on Chord that follows this approach, and VerDi, a DHT layer built on top of the Verme routing overlay. Simulations show that Verme and VerDi have a low overhead when compared to Chord´s corresponding layers, and that our new overlay design helps containing, or at least slowing down the propagation of topological worms.
  • Keywords
    invasive software; peer-to-peer computing; telecommunication security; DHT layer; VerDi; Verme; peer-to-peer overlay network; topological worms; worm propagation strategy; Analytical models; Delay effects; Internet; Network topology; Peer to peer computing; Probes; Routing; Software systems; Surveillance; Viruses (medical);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
  • Conference_Location
    Lisbon
  • Print_ISBN
    978-1-4244-4422-9
  • Electronic_ISBN
    978-1-4244-4421-2
  • Type

    conf

  • DOI
    10.1109/DSN.2009.5270341
  • Filename
    5270341