Anomaly detection for Internet worms

Anomaly detection for Internet worms
复制标题

互联网蠕虫异常检测

DOI:
10.1109/inm.2005.1440779
复制
发表时间:
2005
期刊:
2005 9th IFIP/IEEE International Symposium on Integrated Network Management, 2005. IM 2005.
影响因子:
--
通讯作者:
C. Leckie
C. Leckie
中科院分区:
--
文献类型:
--
作者:
Yousof Al;C. Leckie

文献摘要

被引文献

相似文献

互联网蠕虫已经成为互联网的主要威胁,因为它们能够迅速危害大量计算机。为了应对这种威胁,人们越来越需要有效的技术来检测蠕虫的存在并减少蠕虫的传播。此外,现有的新蠕虫异常检测方法存在可扩展性问题。在本文中,我们提出了一种方法来检测蠕虫的连接活动的相似模式的基础上。然后,我们研究如何提高蠕虫检测的计算效率,提出了一个贪婪的算法,它最大限度地减少了检测蠕虫所需的流量处理量,从而增加了系统的可扩展性。我们的评估表明,贪婪算法不仅实现了高检测精度,减少了大量的处理时间来检测蠕虫,但也实现了合理的蠕虫流量检测在早期阶段的爆发。
Internet worms have become a major threat to the Internet due to their ability to rapidly compromise large numbers of computers. In response to this threat, there is a growing demand for effective techniques to detect the presence of worms and to reduce the worms' spread. Furthermore, existing approaches for anomaly detection of new worms suffer from scalability problems. In this paper, we present an approach for detecting worms based on similar patterns of connection activity. We then investigate how to improve the computational efficiency of worm detection by presenting a greedy algorithm, which minimizes the amount of traffic processing needed to detect worms, thus increasing the scalability of the system. Our evaluation shows that the greedy algorithm not only achieved high detection accuracy and reduced the amount of processing time to detect worms, but also achieved reasonable worm traffic detection in the early stages of an outbreak.