DocumentCode
893043
Title
DAW: A Distributed Antiworm System
Author
Chen, Shigang ; Tang, Yong
Author_Institution
Univ. of Florida, Gainesville
Volume
18
Issue
7
fYear
2007
fDate
7/1/2007 12:00:00 AM
Firstpage
893
Lastpage
906
Abstract
A worm automatically replicates itself across networks and may infect millions of servers in a short period of time. It is conceivable that the cyberterrorists may use a widespread worm to cause major disruption to the Internet economy. Much recent research concentrates on propagation models and early warning, but the defense against worms is largely an open problem. We propose a distributed antiworm architecture (DAW) that automatically slows down or even halts the worm propagation within an Internet service provider (ISP) network. New defense techniques are developed based on the behavioral difference between normal hosts and worm-infected hosts. Particularly, a worm-infected host has a much higher connection-failure rate when it randomly scans the Internet. This property allows DAW to set the worms apart from the normal hosts. We propose a temporal rate-limit algorithm and a spatial rate-limit algorithm, which makes the speed of worm propagation configurable by the parameters of the defense system. The effectiveness of the new techniques is evaluated analytically and by simulations.
Keywords
Internet; invasive software; DAW; Internet; cyberterrorists; distributed antiworm architecture; spatial rate-limit algorithm; temporal rate-limit algorithm; worm propagation; Analytical models; Asia; Computer worms; Europe; Network servers; Protocols; Service oriented architecture; Viruses (medical); Web and internet services; Web server; Internet worms; network security; rate-limit algorithms.;
fLanguage
English
Journal_Title
Parallel and Distributed Systems, IEEE Transactions on
Publisher
ieee
ISSN
1045-9219
Type
jour
DOI
10.1109/TPDS.2007.1033
Filename
4218570
Link To Document