DocumentCode
501671
Title
PAIDS: A Proximity-Assisted Intrusion Detection System for Unidentified Worms
Author
Zhuang, Zhenyun ; Li, Ying ; Chen, Zesheng
Author_Institution
Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
Volume
1
fYear
2009
fDate
20-24 July 2009
Firstpage
392
Lastpage
399
Abstract
The wide spread of worms poses serious challenges to today´s Internet.Various IDSes (intrusion detection systems) have been proposed to identify or prevent such spread. These IDSes can be largely classified as signature-based or anomaly-based ones depending on what type of knowledge the system knows. Signature-based IDSes are unable to detect the outbreak of new and unidentified worms when the worms´ characteristic patterns are unknown. In addition, new worms are often sufficiently intelligent to hide their activities and evade anomaly detection. Moreover, modern worms tend to spread more quickly, and the outbreak period lasts in the order of hours or even minutes. Such characteristics render existing detection mechanisms less effective.In this work, we consider the drawbacks of current detection approaches and propose PAIDS, a proximity-assisted IDS approach for identifying the outbreak of unknown worms. PAIDS does not rely on signatures.Instead, it takes advantage of the proximity information of compromised hosts. PAIDS operates on an orthogonal dimension with existing IDS approaches and can thus work collaboratively with existing IDSes to achieve better performance. We test the effectiveness of PAIDS with trace-driven simulations and show that PAIDS has a high detection rate and a low false positive rate.
Keywords
Internet; digital signatures; invasive software; Internet; PAIDS; anomaly detection; proximity-assisted intrusion detection system; signature-based scheme; unidentified worm; Application software; Collaborative work; Computer applications; Computer worms; Educational institutions; Failure analysis; Impedance; Internet; Intrusion detection; Pattern analysis; Intrusion Detection System; Proximity; Worm;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
Conference_Location
Seattle, WA
ISSN
0730-3157
Print_ISBN
978-0-7695-3726-9
Type
conf
DOI
10.1109/COMPSAC.2009.59
Filename
5254234
Link To Document