A multi-resolution approach for worm detection and containment

被引:21
|
作者
Sekar, Vyas [1 ]
Xie, Yinglian [1 ]
Reiter, Michael K. [1 ]
Zhang, Hui [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
关键词
D O I
10.1109/DSN.2006.6
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Despite the proliferation of detection and containment techniques in the worm defense literature, simple threshold-based methods remain the most widely deployed and most popular approach among practitioners. This popularity arises out of the simplistic appeal, ease of use, and independence from attack-specific properties such as scanning strategies and signatures. However, such approaches have known limitations: they either fail to detect low-rate attacks or incur very high false positive rates. We propose a multi-resolution approach to enhance the power of threshold-based detection and rate-limiting techniques. Using such an approach we can not only detect fast attacks with low latency, but also discover low-rate attacks - several orders of magnitude less aggressive than today's fast propagating attacks - with low false positive rates. We also outline a multi-resolution rate limiting mechanism for throttling the number of new connections a host can make, to contain the spread of worms. Our trace analysis and simulation experiments demonstrate the benefits of a multiresolution approach for worm defense.
引用
收藏
页码:189 / 198
页数:10
相关论文
共 50 条
  • [1] A Modified Multi-Resolution Approach for Port Scan Detection
    Moon, Hwashin
    Yi, Sungwon
    Cho, Keeseong
    2010 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE GLOBECOM 2010, 2010,
  • [2] Multi-resolution corner detection
    Pedersini, F
    Pozzoli, E
    Sarti, A
    Tubaro, S
    2000 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL III, PROCEEDINGS, 2000, : 881 - 884
  • [3] Multi-resolution fuzzy approach for singularity detection in fingerprint images
    Vizcaya, PR
    Gerhardt, LA
    SURVEILLANCE AND ASSESSMENT TECHNOLOGIES FOR LAW ENFORCEMENT, 1997, 2935 : 46 - 56
  • [4] A multi-resolution approach for line-edge roughness detection
    Sun, Wei
    Mukherjee, Rajib
    Stroeve, Pieter
    Palazoglu, Ahmet
    Romagnoli, Jose A.
    MICROELECTRONIC ENGINEERING, 2009, 86 (03) : 340 - 351
  • [5] A multi-resolution approach to singular point detection in fingerprint images
    Wang, CF
    Gavrilova, ML
    IC-AI '04 & MLMTA'04 , VOL 1 AND 2, PROCEEDINGS, 2004, : 506 - 511
  • [6] Multi-resolution approach to periodicity detection based on wavelet transform
    Xu, Zhan-Yang
    Zhan, Charles
    Zhang, Shun-Yi
    Yingyong Kexue Xuebao/Journal of Applied Sciences, 2010, 28 (01): : 60 - 64
  • [7] A Multi-Resolution Approach For Edge Detection Using Ant Colony Optimization
    Ashir, Abubakar M.
    Eleyan, Alaa
    2015 23RD SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2015, : 1777 - 1780
  • [8] A multi-resolution approach for infrared vision-based pedestrian detection
    Broggi, A
    Fascioli, A
    Carletti, M
    Graf, T
    Meinecke, M
    2004 IEEE INTELLIGENT VEHICLES SYMPOSIUM, 2004, : 7 - 12
  • [9] A multi-resolution approach to electromagnetic modelling
    Cherevatova, M.
    Egbert, G. D.
    Smirnov, M. Yu.
    GEOPHYSICAL JOURNAL INTERNATIONAL, 2018, 214 (01) : 656 - 671
  • [10] Multi-resolution approach to strain imaging
    Dey, J
    Mai, JJ
    Insana, MF
    2000 IEEE ULTRASONICS SYMPOSIUM PROCEEDINGS, VOLS 1 AND 2, 2000, : 1853 - 1856