NADTW: new approach for detecting TCP worm.

Saved in:
Bibliographic Details
Title: NADTW: new approach for detecting TCP worm.
Authors: Anbar, Mohammed1 anbar@nav6.usm.my, Abdullah, Rosni rosni@usm.my, Munther, Alhamza2 alhamza.munther@gmail.com, Al-Betar, Mohammed3 mohbetar@cs.usm.my, Saad, Redhwan1 redhwan@nav6.usm.my
Source: Neural Computing & Applications. Dec2017 Supplement 1, Vol. 28, p525-538. 14p.
Subjects: Computer worms, Malware, Intrusion detection systems (Computer security), Computer network security, TCP/IP, Bandwidths
Abstract: A computer worm is a self-replicating malicious code that does not alter files but resides in active memory where it duplicates itself. Worms use parts of the operating system that are automatic and usually invisible to the user. Worms commonly exhibit abnormal behaviors, which become noticeable only when their uncontrolled replication consumes system resources and consequently decelerates or halts other tasks completely. This paper proposes an effective approach for detecting the presence of TCP network worms. This approach consists of two phases: Statistical Cross-relation for Network Scanning (SCANS) phase and the Worm Correlation phase. The SCANS phase is used to detect the presence of the network scanning behavior of a network worm, while the worm correlation phase is used to detect the Destination Source Correlation (DSC) behavior of the network worm. The proposed approach has been tested with a simulated dataset obtained from the GTNetS simulator. The numerical results showed that the proposed approach is efficient and outperforms the well-known DSC approach in terms of detecting the presence of TCP network worm. [ABSTRACT FROM AUTHOR]
Copyright of Neural Computing & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 126403743
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: NADTW: new approach for detecting TCP worm.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Anbar%2C+Mohammed%22">Anbar, Mohammed</searchLink><relatesTo>1</relatesTo><i> anbar@nav6.usm.my</i><br /><searchLink fieldCode="AR" term="%22Abdullah%2C+Rosni%22">Abdullah, Rosni</searchLink><i> rosni@usm.my</i><br /><searchLink fieldCode="AR" term="%22Munther%2C+Alhamza%22">Munther, Alhamza</searchLink><relatesTo>2</relatesTo><i> alhamza.munther@gmail.com</i><br /><searchLink fieldCode="AR" term="%22Al-Betar%2C+Mohammed%22">Al-Betar, Mohammed</searchLink><relatesTo>3</relatesTo><i> mohbetar@cs.usm.my</i><br /><searchLink fieldCode="AR" term="%22Saad%2C+Redhwan%22">Saad, Redhwan</searchLink><relatesTo>1</relatesTo><i> redhwan@nav6.usm.my</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Neural+Computing+%26+Applications%22">Neural Computing & Applications</searchLink>. Dec2017 Supplement 1, Vol. 28, p525-538. 14p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+worms%22">Computer worms</searchLink><br /><searchLink fieldCode="DE" term="%22Malware%22">Malware</searchLink><br /><searchLink fieldCode="DE" term="%22Intrusion+detection+systems+%28Computer+security%29%22">Intrusion detection systems (Computer security)</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22TCP%2FIP%22">TCP/IP</searchLink><br /><searchLink fieldCode="DE" term="%22Bandwidths%22">Bandwidths</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: A computer worm is a self-replicating malicious code that does not alter files but resides in active memory where it duplicates itself. Worms use parts of the operating system that are automatic and usually invisible to the user. Worms commonly exhibit abnormal behaviors, which become noticeable only when their uncontrolled replication consumes system resources and consequently decelerates or halts other tasks completely. This paper proposes an effective approach for detecting the presence of TCP network worms. This approach consists of two phases: Statistical Cross-relation for Network Scanning (SCANS) phase and the Worm Correlation phase. The SCANS phase is used to detect the presence of the network scanning behavior of a network worm, while the worm correlation phase is used to detect the Destination Source Correlation (DSC) behavior of the network worm. The proposed approach has been tested with a simulated dataset obtained from the GTNetS simulator. The numerical results showed that the proposed approach is efficient and outperforms the well-known DSC approach in terms of detecting the presence of TCP network worm. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Neural Computing & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=126403743
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s00521-016-2358-9
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 14
        StartPage: 525
    Subjects:
      – SubjectFull: Computer worms
        Type: general
      – SubjectFull: Malware
        Type: general
      – SubjectFull: Intrusion detection systems (Computer security)
        Type: general
      – SubjectFull: Computer network security
        Type: general
      – SubjectFull: TCP/IP
        Type: general
      – SubjectFull: Bandwidths
        Type: general
    Titles:
      – TitleFull: NADTW: new approach for detecting TCP worm.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Anbar, Mohammed
      – PersonEntity:
          Name:
            NameFull: Abdullah, Rosni
      – PersonEntity:
          Name:
            NameFull: Munther, Alhamza
      – PersonEntity:
          Name:
            NameFull: Al-Betar, Mohammed
      – PersonEntity:
          Name:
            NameFull: Saad, Redhwan
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 02
              M: 12
              Text: Dec2017 Supplement 1
              Type: published
              Y: 2017
          Identifiers:
            – Type: issn-print
              Value: 09410643
          Numbering:
            – Type: volume
              Value: 28
          Titles:
            – TitleFull: Neural Computing & Applications
              Type: main
ResultId 1