Effective worm detection for various scan techniques.

Saved in:
Bibliographic Details
Title: Effective worm detection for various scan techniques.
Authors: Xia, Jianhong1 jxia@ecs.umass, Vangala, Sarma1 svangala@ecs.umass, Wu, Jiang1 jiawu@ecs.umass, Gao, Lixin1 lgao@ecs.umass, Kwiat, Kevin2 kwiatk@rl.af.mil
Source: Journal of Computer Security. 2006, Vol. 14 Issue 4, p359-387. 29p. 2 Diagrams, 2 Charts, 10 Graphs.
Subjects: Computer viruses, Computer virus prevention, Computer software, Data protection, Anomaly detection (Computer security), Algorithm software, Computer network security, Firewalls (Computer security)
Abstract: In recent years, the threats and damages caused by active worms have become more and more serious. In order to reduce the loss caused by fast-spreading active worms, an effective detection mechanism to quickly detect worms is desired. In this paper, we first explore various scan strategies used by worms on finding vulnerable hosts. We show that targeted worms spread much faster than random scan worms. We then present a generic worm detection architecture to monitor malicious worm activities. We propose and evaluate our detection mechanism called Victim Number Based Algorithm. We show that our detection algorithm is effective and able to detect worm events before 2% of vulnerable hosts are infected for most scenarios. Furthermore, in order to reduce false alarms, we propose an integrated approach using multiple parameters as indicators to detect worm events. The results suggest that our integrated approach can differentiate worm attacks from DDoS attacks and benign scans. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 22976132
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Effective worm detection for various scan techniques.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Xia%2C+Jianhong%22">Xia, Jianhong</searchLink><relatesTo>1</relatesTo><i> jxia@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Vangala%2C+Sarma%22">Vangala, Sarma</searchLink><relatesTo>1</relatesTo><i> svangala@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Wu%2C+Jiang%22">Wu, Jiang</searchLink><relatesTo>1</relatesTo><i> jiawu@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Gao%2C+Lixin%22">Gao, Lixin</searchLink><relatesTo>1</relatesTo><i> lgao@ecs.umass</i><br /><searchLink fieldCode="AR" term="%22Kwiat%2C+Kevin%22">Kwiat, Kevin</searchLink><relatesTo>2</relatesTo><i> kwiatk@rl.af.mil</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2006, Vol. 14 Issue 4, p359-387. 29p. 2 Diagrams, 2 Charts, 10 Graphs.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+viruses%22">Computer viruses</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+virus+prevention%22">Computer virus prevention</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+software%22">Computer software</searchLink><br /><searchLink fieldCode="DE" term="%22Data+protection%22">Data protection</searchLink><br /><searchLink fieldCode="DE" term="%22Anomaly+detection+%28Computer+security%29%22">Anomaly detection (Computer security)</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithm+software%22">Algorithm software</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22Firewalls+%28Computer+security%29%22">Firewalls (Computer security)</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: In recent years, the threats and damages caused by active worms have become more and more serious. In order to reduce the loss caused by fast-spreading active worms, an effective detection mechanism to quickly detect worms is desired. In this paper, we first explore various scan strategies used by worms on finding vulnerable hosts. We show that targeted worms spread much faster than random scan worms. We then present a generic worm detection architecture to monitor malicious worm activities. We propose and evaluate our detection mechanism called Victim Number Based Algorithm. We show that our detection algorithm is effective and able to detect worm events before 2% of vulnerable hosts are infected for most scenarios. Furthermore, in order to reduce false alarms, we propose an integrated approach using multiple parameters as indicators to detect worm events. The results suggest that our integrated approach can differentiate worm attacks from DDoS attacks and benign scans. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=22976132
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-2006-14403
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 29
        StartPage: 359
    Subjects:
      – SubjectFull: Computer viruses
        Type: general
      – SubjectFull: Computer virus prevention
        Type: general
      – SubjectFull: Computer software
        Type: general
      – SubjectFull: Data protection
        Type: general
      – SubjectFull: Anomaly detection (Computer security)
        Type: general
      – SubjectFull: Algorithm software
        Type: general
      – SubjectFull: Computer network security
        Type: general
      – SubjectFull: Firewalls (Computer security)
        Type: general
    Titles:
      – TitleFull: Effective worm detection for various scan techniques.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Xia, Jianhong
      – PersonEntity:
          Name:
            NameFull: Vangala, Sarma
      – PersonEntity:
          Name:
            NameFull: Wu, Jiang
      – PersonEntity:
          Name:
            NameFull: Gao, Lixin
      – PersonEntity:
          Name:
            NameFull: Kwiat, Kevin
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 08
              Text: 2006
              Type: published
              Y: 2006
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 14
            – Type: issue
              Value: 4
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1