Detecting intra-enterprise scanning worms based on address resolution

Detecting intra-enterprise scanning worms based on address resolution
复制标题

基于地址解析的企业内部扫描蠕虫检测

DOI:
10.1109/csac.2005.20
复制
发表时间:
2005
期刊:
21st Annual Computer Security Applications Conference (ACSAC'05)
影响因子:
--
通讯作者:
E. Kranakis
E. Kranakis
中科院分区:
--
文献类型:
--
作者:
D. Whyte;P. V. Oorschot;E. Kranakis

文献摘要

被引文献

相似文献

基于特征码的互联网蠕虫检测方案往往在零日蠕虫上失败,并且它们对新威胁的快速反应能力通常受到某种形式的人类参与来制定更新的攻击特征码的要求的限制。我们提出了一种基于异常的检测技术,详细介绍了一种方法来检测单个网络单元内的扫描蠕虫的传播,从而保护内部网络免受内部客户端的感染。我们的软件实现表明,这种技术是准确和快速的,足以使自动遏制和抑制蠕虫传播的网络单元内。我们的方法依赖于一个聚合的异常分数,来自于地址解析协议(阿普)活动的相关性,从个人网络连接设备。我们的初步分析和原型表明,这种技术可以用来快速检测零日蠕虫在一个非常小的扫描次数
Signature-based schemes for detecting Internet worms often fail on zero-day worms, and their ability to rapidly react to new threats is typically limited by the requirement of some form of human involvement to formulate updated attack signatures. We propose an anomaly-based detection technique detailing a method to detect propagation of scanning worms within individual network cells, thus protecting internal networks from infection by internal clients. Our software implementation indicates that this technique is both accurate and rapid enough to enable automatic containment and suppression of worm propagation within a network cell. Our approach relies on an aggregate anomaly score, derived from the correlation of address resolution protocol (ARP) activity from individual network attached devices. Our preliminary analysis and prototype indicate that this technique can be used to rapidly detect zero-day worms within a very small number of scans