Detecting Unknown Worms Using Randomness Check(Internet)
スポンサーリンク
概要
- 論文の詳細を見る
From the introduction of CodeRed and Slammer worms, it has been learned that the early detection of worm epidemics is important in order to reduce the damage resulting from outbreaks. A prominent characteristic of Internet worms is the random selection of subsequent targets. In this paper, we propose a new worm detection mechanism by checking the random distribution of destination addresses in network traffic. The proposed mechanism constructs a matrix from network traffic and checks the rank of the matrix in order to detect the spreading of Internet worms. From the fact that a random binary matrix holds a high rank value, ADUR (Anomaly Detection Using Randomness check) is proposed for detecting unknown worms based on the rank of the matrix. From experiments on various environments, it is demonstrated that the ADUR mechanism effectively detects the spread of new worms in the early stages, even when there is only a single host infected in a monitoring network. Also, we show that ADUR is highly sensitive so that the worm epidemic can be detectable quickly, e.g., three times earlier than the infection of 90% vulnerable hosts.
- 社団法人電子情報通信学会の論文
- 2007-04-01
著者
-
KIM Hyogon
Department of Computer Science and Engineering, Korea University
-
LEE Heejo
Department of Computer Science and Engineering, Korea University
-
Kim Hyogon
Department Of Computer Science And Engineering Korea University
-
PARK Hyundo
Department of Computer Science and Engineering, Korea University
-
Park Hyundo
Department Of Computer Science And Engineering Korea University
-
Lee Heejo
Department Of Computer Science And Engineering Korea University
関連論文
- A Seamless Lawful Interception Triggering Architecture for the Heterogeneous Wireless Networks
- A Seamless Lawful Interception Triggering Architecture for the Heterogeneous Wireless Networks
- Optimal Scheduling for Real-Time Parallel Tasks(Algorithm Theory)
- Error Bound of Collision Probability Estimation in Non-saturated IEEE802.11 WLANs(Terrestrial Radio Communications)
- On the Cross-Layer Impact of TCP ACK Thinning on IEEE802.11 Wireless MAC Dynamics(Wireless Communication Technologies)
- Boosting VoIP Capacity of Wireless Mesh Networks through Lazy Frame Aggregation(Terrestrial Radio Communications)
- Detecting Unknown Worms Using Randomness Check(Internet)
- Evaluation of Two Load-Balancing Primary-Backup Process Allocation Schemes
- An Adaptive Routing Method for VoIP Gateways Based on Packet Delay Information(Network)
- Resiliency of Network Topologies under Path-Based Attacks(Internet)