A Stochastic Framework for Prediction of Malware Spreading in Heterogeneous Networks

被引:11
作者
Koenig, Sandra [1 ]
Schauer, Stefan [1 ]
Rass, Stefan [2 ]
机构
[1] Austrian Inst Technol GmbH, Digital Safety & Secur Dept, Klagenfurt, Austria
[2] Univ Klagenfurt, Syst Secur Grp, Inst Appl Informat, Klagenfurt, Austria
来源
SECURE IT SYSTEMS, NORDSEC 2016 | 2016年 / 10014卷
基金
欧盟第七框架计划;
关键词
PROPAGATION; INTERNET; PERCOLATION; EPIDEMICS; DISEASE;
D O I
10.1007/978-3-319-47560-8_5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The infection of ICT systems with malware has become an increasing threat in the past years. In most cases, large-scale cybe-rattacks are initiated by the establishment of a botnet, by infecting a large number of computers with malware to launch the actual attacks subsequently with help of the infected victim machines (e.g., a distributed denial-of-service or similar). To prevent such an infection, several methodologies and technical solutions like firewalls, malware scanners or intrusion detection systems are usually applied. Nevertheless, malware becomes more sophisticated and is often able to surpass these preventive actions. Hence, it is more relevant for ICT risk managers to assess the spreading of a malware infection within an organization's network. In this paper, we present a novel framework based on stochastic models from the field of disease spreading to describe the propagation of malware within a network, with an explicit account for different infection routes (phishing emails, network shares, etc.). This approach allows the user not only to estimate the number of infected nodes in the network but also provides a simple criterion to check whether an infection may grow into a epidemic. Unlike many other techniques, our framework is not limited to a particular communication technology, but can unify different types of infection channels (e.g., physical, logical and social links) within the same model. We will use three simple examples to illustrate the functionalities of the framework.
引用
收藏
页码:67 / 81
页数:15
相关论文
共 41 条
[1]  
[Anonymous], ARXIV160403558
[2]  
[Anonymous], ARXIV E PRINTS
[3]  
[Anonymous], ARXIV151108591
[4]  
Beck A., 2016, ENTWICKLUNG METRIK A
[5]   Network robustness and fragility: Percolation on random graphs [J].
Callaway, DS ;
Newman, MEJ ;
Strogatz, SH ;
Watts, DJ .
PHYSICAL REVIEW LETTERS, 2000, 85 (25) :5468-5471
[6]   Spatial-temporal modeling of malware propagation in networks [J].
Chen, ZS ;
Ji, CY .
IEEE TRANSACTIONS ON NEURAL NETWORKS, 2005, 16 (05) :1291-1303
[7]   Breakdown of the internet under intentional attack [J].
Cohen, R ;
Erez, K ;
ben-Avraham, D ;
Havlin, S .
PHYSICAL REVIEW LETTERS, 2001, 86 (16) :3682-3685
[8]   Resilience of the Internet to random breakdowns [J].
Cohen, R ;
Erez, K ;
ben-Avraham, D ;
Havlin, S .
PHYSICAL REVIEW LETTERS, 2000, 85 (21) :4626-4628
[9]   Percolation critical exponents in scale-free networks [J].
Cohen, R ;
ben-Avraham, D ;
Havlin, S .
PHYSICAL REVIEW E, 2002, 66 (03) :1-036113
[10]   On the Lambert W function [J].
Corless, RM ;
Gonnet, GH ;
Hare, DEG ;
Jeffrey, DJ ;
Knuth, DE .
ADVANCES IN COMPUTATIONAL MATHEMATICS, 1996, 5 (04) :329-359