Effective worm detection for various scan techniques.
Saved in:
| Title: | Effective worm detection for various scan techniques. |
|---|---|
| Authors: | Xia, Jianhong1 jxia@ecs.umass, Vangala, Sarma1 svangala@ecs.umass, Wu, Jiang1 jiawu@ecs.umass, Gao, Lixin1 lgao@ecs.umass, Kwiat, Kevin2 kwiatk@rl.af.mil |
| Source: | Journal of Computer Security. 2006, Vol. 14 Issue 4, p359-387. 29p. 2 Diagrams, 2 Charts, 10 Graphs. |
| Subjects: | Computer viruses, Computer virus prevention, Computer software, Data protection, Anomaly detection (Computer security), Algorithm software, Computer network security, Firewalls (Computer security) |
| Abstract: | In recent years, the threats and damages caused by active worms have become more and more serious. In order to reduce the loss caused by fast-spreading active worms, an effective detection mechanism to quickly detect worms is desired. In this paper, we first explore various scan strategies used by worms on finding vulnerable hosts. We show that targeted worms spread much faster than random scan worms. We then present a generic worm detection architecture to monitor malicious worm activities. We propose and evaluate our detection mechanism called Victim Number Based Algorithm. We show that our detection algorithm is effective and able to detect worm events before 2% of vulnerable hosts are infected for most scenarios. Furthermore, in order to reduce false alarms, we propose an integrated approach using multiple parameters as indicators to detect worm events. The results suggest that our integrated approach can differentiate worm attacks from DDoS attacks and benign scans. [ABSTRACT FROM AUTHOR] |
| Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Links: – Type: pdflink Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 22976132 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Effective worm detection for various scan techniques. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Xia%2C+Jianhong%22">Xia, Jianhong</searchLink><relatesTo>1</relatesTo><i> jxia@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Vangala%2C+Sarma%22">Vangala, Sarma</searchLink><relatesTo>1</relatesTo><i> svangala@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Wu%2C+Jiang%22">Wu, Jiang</searchLink><relatesTo>1</relatesTo><i> jiawu@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Gao%2C+Lixin%22">Gao, Lixin</searchLink><relatesTo>1</relatesTo><i> lgao@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Kwiat%2C+Kevin%22">Kwiat, Kevin</searchLink><relatesTo>2</relatesTo><i> kwiatk@rl.af.mil</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2006, Vol. 14 Issue 4, p359-387. 29p. 2 Diagrams, 2 Charts, 10 Graphs. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Computer+viruses%22">Computer viruses</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+virus+prevention%22">Computer virus prevention</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+software%22">Computer software</searchLink><br /><searchLink fieldCode="DE" term="%22Data+protection%22">Data protection</searchLink><br /><searchLink fieldCode="DE" term="%22Anomaly+detection+%28Computer+security%29%22">Anomaly detection (Computer security)</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithm+software%22">Algorithm software</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22Firewalls+%28Computer+security%29%22">Firewalls (Computer security)</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: In recent years, the threats and damages caused by active worms have become more and more serious. In order to reduce the loss caused by fast-spreading active worms, an effective detection mechanism to quickly detect worms is desired. In this paper, we first explore various scan strategies used by worms on finding vulnerable hosts. We show that targeted worms spread much faster than random scan worms. We then present a generic worm detection architecture to monitor malicious worm activities. We propose and evaluate our detection mechanism called Victim Number Based Algorithm. We show that our detection algorithm is effective and able to detect worm events before 2% of vulnerable hosts are infected for most scenarios. Furthermore, in order to reduce false alarms, we propose an integrated approach using multiple parameters as indicators to detect worm events. The results suggest that our integrated approach can differentiate worm attacks from DDoS attacks and benign scans. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=22976132 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.3233/JCS-2006-14403 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 29 StartPage: 359 Subjects: – SubjectFull: Computer viruses Type: general – SubjectFull: Computer virus prevention Type: general – SubjectFull: Computer software Type: general – SubjectFull: Data protection Type: general – SubjectFull: Anomaly detection (Computer security) Type: general – SubjectFull: Algorithm software Type: general – SubjectFull: Computer network security Type: general – SubjectFull: Firewalls (Computer security) Type: general Titles: – TitleFull: Effective worm detection for various scan techniques. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Xia, Jianhong – PersonEntity: Name: NameFull: Vangala, Sarma – PersonEntity: Name: NameFull: Wu, Jiang – PersonEntity: Name: NameFull: Gao, Lixin – PersonEntity: Name: NameFull: Kwiat, Kevin IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 08 Text: 2006 Type: published Y: 2006 Identifiers: – Type: issn-print Value: 0926227X Numbering: – Type: volume Value: 14 – Type: issue Value: 4 Titles: – TitleFull: Journal of Computer Security Type: main |
| ResultId | 1 |