A distributed host-based worm detection system

A distributed host-based worm detection system
复制标题

一种基于主机的分布式蠕虫检测系统

DOI:
10.1145/1162666.1162668
复制
发表时间:
2006
期刊:
--
影响因子:
--
通讯作者:
E. Schooler
E. Schooler
中科院分区:
--
文献类型:
--
作者:
Senthilkumar G. Cheetancheri;John Mark Agosta;D. Dash;K. Levitt;J. Rowe;E. Schooler

文献摘要

被引文献

相似文献

提出了一种仅使用终端主机检测器检测大规模蠕虫攻击的方法。这些检测器向合作伙伴传播和聚合警报,以检测正在进行的大规模分布式攻击。事实上,基于主机的检测器的特性在隔离方面可能相对较差,但当共同考虑时,会导致高质量的分布式蠕虫检测器。我们实现了一种协作警报共享协议,并结合分布式序贯假设检验来生成有关分布式攻击的全局警报。我们评估了系统在存在各种错误警报条件和存在互联网蠕虫攻击的情况下的响应。我们的评估是与Emulab上的工程师一起进行的,并使用真实的操作系统和计算平台来阻止仿真试验台。
We present a method for detecting large-scale worm attacks using only end-host detectors. These detectors propagate and aggregate alerts to cooperating partners to detect large-scale distributed attacks in progress. The properties of the host-based detectors may in fact be relatively poor in isolation but when taken collectively result in a high-quality distributed worm detector. We implement a cooperative alert sharing protocol coupled with distributed sequential hypothesis testing to generate global alarms about distributed attacks. We evaluate the system's response in the presence of a variety of false alarm conditions and in the presence of an Internet worm attack. Our evaluation is conducted with agents on the Emulab and DETER emulated testbeds using real operating systems and computing platforms.