Dynamic control of worm propagation

被引:10
作者
Dantu, R [1 ]
Cangussu, J [1 ]
Yelimeli, A [1 ]
机构
[1] Univ N Texas, Denton, TX 76203 USA
来源
ITCC 2004: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, VOL 1, PROCEEDINGS | 2004年
关键词
D O I
10.1109/ITCC.2004.1286491
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In a computer network, network security is accomplished using elements like firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm in priori to detect the attack. Modern day viruses like Code red, Sapphire and Nimda spread very fast. For example, Sapphire can double its size and infect more than 90% of the vulnerable hosts within 10 minutes. Therefore it is impractical if not impossible for human mediated responses to these modern day fast spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control is an effective method in containing the damage. In this paper we propose a state space feedback control model to detect and control the spread of these viruses by measuring the number of connections an infected host makes. The objective of the mechanism is to slow down the spreading velocity of a worm by controlling (delaying) the total number of connections made by an infected host. As expected, the model showed that the sooner the infection is detected the faster the reduction of the spreading velocity. Additionally, the deployment of a controller at different levels (host and firewall) has shown to be very promising.
引用
收藏
页码:419 / 423
页数:5
相关论文
共 7 条
  • [1] A formal model of the software test process
    Cangussu, JW
    DeCarlo, RA
    Mathur, AP
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2002, 28 (08) : 782 - 796
  • [2] Dantu R. V., 2002, ACSA WORKSH APPL ENG
  • [3] DANTU RV, 2002, 18 ANN ACSCA C PRACT
  • [4] GANDHI N, 2002, P AM CONTR C ANCH AK
  • [5] MOORE D, SPREAD SAPPHIRE WORM
  • [6] Staniford S, 2002, USENIX ASSOCIATION PROCEEDINGS OF THE 11TH USENIX SECURITY SYMPOSIUM, P149
  • [7] Throttling Viruses: Restricting propagation to defeat malicious mobile code
    Williamson, MM
    [J]. 18TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2002, : 61 - 68