Detecting Internet worms at early stage

被引:5
作者
Chen, SG [1 ]
Ranka, S [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
关键词
early warning system; enterprise security management; Internet worm;
D O I
10.1109/JSAC.2005.854124
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Managing the security of enterprise networks has emerged to be a critical problem in the era of Internet economy. Arising as a leading threat, worms repetitively caused enormous damage to the Internet community during the past years. A new security service that monitors the ongoing worm activities on the Internet will greatly contribute to the security management of modern enterprise networks. This paper proposes an Internet-worm early warning system that automatically detects concerted scan activities and derives possible signatures of worm attacks. Its goal is to issue warning at the early stage of worm propagation and to provide necessary information for security analysts to control the damage. It reduces false positives by filtering out false scan sources. The system is locally deployable or can be codeployed amongst a group of enterprise networks. We provide both analytical and simulation studies on the responsiveness of this early warning system.
引用
收藏
页码:2003 / 2012
页数:10
相关论文
共 18 条
[1]  
*CERT, 2001, 200126 CERT
[2]  
*CERT, 2003, CA200304 MSSQL
[3]  
*CERT, 2001, CA200123 CERT
[4]   Slowing down Internet worms [J].
Chen, SG ;
Tang, Y .
24TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 2004, :312-319
[5]  
Chen ZS, 2003, IEEE INFOCOM SER, P1890
[6]   The mathematics of infectious diseases [J].
Hethcote, HW .
SIAM REVIEW, 2000, 42 (04) :599-653
[7]  
KNUTH DE, 1977, SIAM J COMPUT JUN
[8]   A mixed abstraction level simulation model of large-scale Internet worm infestations [J].
Ljenstam, M ;
Yuan, YG ;
Premore, BJ ;
Nicol, D .
MASCOTS 2002: 10TH IEEE INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS, AND SIMULATION OF COMPUTER AND TELECOMMUNICATIONS SYSTEMS, PROCEEDINGS, 2002, :109-116
[9]  
Moore D, 2003, IEEE INFOCOM SER, P1901
[10]   WITH MICROSCOPE AND TWEEZERS - THE WORM FROM MITS PERSPECTIVE [J].
ROCHLIS, JA ;
EICHIN, MW .
COMMUNICATIONS OF THE ACM, 1989, 32 (06) :689-698