A distributed host-based worm detection system
A distributed host-based worm detection system
复制标题
一种基于主机的分布式蠕虫检测系统
DOI:
10.1145/1162666.1162668
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
E. Schooler
中科院分区:
文献类型:
--
作者:
Senthilkumar G. Cheetancheri;John Mark Agosta;D. Dash;K. Levitt;J. Rowe;E. Schooler
We present a method for detecting large-scale worm attacks using only end-host detectors. These detectors propagate and aggregate alerts to cooperating partners to detect large-scale distributed attacks in progress. The properties of the host-based detectors may in fact be relatively poor in isolation but when taken collectively result in a high-quality distributed worm detector. We implement a cooperative alert sharing protocol coupled with distributed sequential hypothesis testing to generate global alarms about distributed attacks. We evaluate the system's response in the presence of a variety of false alarm conditions and in the presence of an Internet worm attack. Our evaluation is conducted with agents on the Emulab and DETER emulated testbeds using real operating systems and computing platforms.