Optimally Identifying Worm-Infected Hosts
スポンサーリンク
概要
- 論文の詳細を見る
We have proposed a method of identifying superspreaders by flow sampling and a method of filtering legitimate hosts from the identified superspreaders using a white list. However, the problem of how to optimally set parameters of φ, the measurement period length, m*, the identification threshold of the flow count m within φ, and H*, the identification probability for hosts with m=m*, remained unsolved. These three parameters seriously impact the ability to identify the spread of infection. Our contributions in this work are two-fold: (1) we propose a method of optimally designing these three parameters to satisfy the condition that the ratio of the number of active worm-infected hosts divided by the number of all vulnerable hosts is bound by a given upper-limit during the time T required to develop a patch or an anti-worm vaccine, and (2) the proposed method can optimize the identification accuracy of worm-infected hosts by maximally using a limited amount of memory resource of monitors.
著者
-
MORI Tatsuya
NTT Network Technology Laboratories, NTT Corporation
-
HARADA Shigeaki
NTT Network Technology Laboratories, NTT Corporation
-
Kamiyama Noriaki
NTT Network Technology Laboratories
-
KAWAHARA Ryoichi
NTT Network Technology Laboratories
関連論文
- Traffic Engineering of Peer-Assisted Content Delivery Network with Content-Oriented Incentive Mechanism
- Analyzing and Reducing the Impact of Traffic on Large-Scale NAT
- Multicast Pre-Distribution VoD System
- Analyzing Spatial Structure of IP Addresses for Detecting Malicious Websites
- Effect of Limiting Pre-Distribution and Clustering Users on Multicast Pre-Distribution VoD
- Optimally Identifying Worm-Infected Hosts
- Optimally Designing ISP-Operated CDN
- Analyzing Characteristics of TCP Quality Metrics with Respect to Type of Connection through Measured Traffic Data
- Analyzing and Reducing the Impact of Traffic on Large-Scale NAT
- Traffic Engineering of Peer-Assisted Content Delivery Network with Content-Oriented Incentive Mechanism
- Analyzing Characteristics of TCP Quality Metrics with Respect to Type of Connection through Measured Traffic Data