Hit-list Worm Detection Using Distributed Sliding Window
スポンサーリンク
概要
- 論文の詳細を見る
In this paper, we propose a new distributed hit-list worm detection method: the Anomaly Connection Tree Method with Distributed Sliding Window (ACTM-DSW). ACTM-DSW employs multiple distributed network Intrusion Detection Systems (IDSs), each of which monitors a small portion of an enterprise network. In ACTM-DSW, worm propagation trees are detected by using a sliding time window. More precisely, the distributed IDSs in ACTM-DSW cooperatively detect tree structures composed of the worms infection connections that have been made within a time window. Through computer-based simulations, we demonstrate that ACTM-DSW outperforms an existing distributed worm detection method, called d-ACTM/VT, for detecting worms whose infection intervals are not constant, but rather have an exponential or uniform distribution. In addition, we implement the distributed IDSs on Xen, a virtual machine environment, and demonstrate the feasibility of the proposed method experimentally.
著者
-
Shigeno Hiroshi
Faculty Of Science And Technology Keio University
-
Kawaguchi Nobutaka
Faculty Of Science And Technology Keio University
関連論文
- NAL Level Stream Authentication for H.264/AVC (特集:シームレスコンピューティングとその応用技術)
- NAL Level Stream Authentication for H.264/AVC
- NAL Level Stream Authentication for H.264/AVC
- Fair Bandwidth Allocation in Diffserv Networks(Network Quality and Control)(Next Generaton Mobile Communications Systems)
- Active Countermeasure Platform against DDoS Attacks(Regular Section)
- Hit-list Worm Detection Using Distributed Sliding Window
- Improvements in TCP Robustness for Asymmetric Bandwidth
- A Real-Time Stream Authentication Scheme for Video Streams (特集:ブロードバンド・ユビキタス・ネットワークとその応用)
- d-ACTM/VT : A Distributed Virtual AC Tree Detection Method(Network Security)
- Improvements in TCP Robustness for Asymmetric Bandwidth
- A Real-Time Stream Authentication Scheme for Video Streams
- A Real-Time Stream Authentication Scheme for Video Streams
- Improvements in TCP Robustness for Asymmetric Bandwidth
- d-ACTM/VT: A Distributed Virtual AC Tree Detection Method
- d-ACTM/VT: A Distributed Virtual AC Tree Detection Method