A multi-resolution approach for worm detection and containment

被引:21
|
作者
Sekar, Vyas [1 ]
Xie, Yinglian [1 ]
Reiter, Michael K. [1 ]
Zhang, Hui [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
关键词
D O I
10.1109/DSN.2006.6
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Despite the proliferation of detection and containment techniques in the worm defense literature, simple threshold-based methods remain the most widely deployed and most popular approach among practitioners. This popularity arises out of the simplistic appeal, ease of use, and independence from attack-specific properties such as scanning strategies and signatures. However, such approaches have known limitations: they either fail to detect low-rate attacks or incur very high false positive rates. We propose a multi-resolution approach to enhance the power of threshold-based detection and rate-limiting techniques. Using such an approach we can not only detect fast attacks with low latency, but also discover low-rate attacks - several orders of magnitude less aggressive than today's fast propagating attacks - with low false positive rates. We also outline a multi-resolution rate limiting mechanism for throttling the number of new connections a host can make, to contain the spread of worms. Our trace analysis and simulation experiments demonstrate the benefits of a multiresolution approach for worm defense.
引用
收藏
页码:189 / 198
页数:10
相关论文
共 50 条
  • [21] A multi-resolution approach to global ocean modeling
    Ringler, Todd
    Petersen, Mark
    Higdon, Robert L.
    Jacobsen, Doug
    Jones, Philip W.
    Maltrud, Mathew
    OCEAN MODELLING, 2013, 69 : 211 - 232
  • [22] Multi-resolution image analysis for vehicle detection
    Hilario, C
    Collado, JM
    Armingol, JM
    de la Escalera, A
    PATTERN RECOGNITION AND IMAGE ANALYSIS, PT 1, PROCEEDINGS, 2005, 3522 : 579 - 586
  • [23] A fast multi-resolution approach to tomographic PIV
    Discetti, Stefano
    Astarita, Tommaso
    EXPERIMENTS IN FLUIDS, 2012, 52 (03) : 765 - 777
  • [24] A multi-resolution approach for optimal mass trasnsport
    Dominitz, Ayelet
    Angenent, Sigurd
    Tannenbaum, Allen
    WAVELET APPLICATIONS IN INDUSTRIAL PROCESSING V, 2007, 6763
  • [25] A multi-resolution approach to hydraulic fracture simulation
    Andre Costa
    Matteo Cusini
    Tao Jin
    Randolph Settgast
    John E. Dolbow
    International Journal of Fracture, 2022, 237 : 165 - 188
  • [26] A Multi-resolution LOD Approach Based on the Viewpoint
    Yu, Wang
    Hua, Xu
    2017 IEEE 2ND ADVANCED INFORMATION TECHNOLOGY, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (IAEAC), 2017, : 983 - 986
  • [27] Multi-resolution Approach to Time Series Retrieval
    Fuad, Muhammad Marwan Muhammad
    Marteau, Pierre-Francois
    PROCEEDINGS OF THE FOURTEENTH INTERNATIONAL DATABASE ENGINEERING & APPLICATIONS SYMPOSIUM (IDEAS '10), 2010, : 136 - 142
  • [28] A Multi-resolution Approach for Atypical Behaviour Mining
    Marascu, Alice
    Masseglia, Florent
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2009, 5476 : 899 - 906
  • [29] MRE: A flexible approach to multi-resolution modeling
    Natrajan, A
    Reynolds, PF
    Srinivasan, S
    11TH WORKSHOP ON PARALLEL AND DISTRIBUTED SIMULATION, PROCEEDINGS, 1997, : 156 - 163
  • [30] A multi-resolution approach to quantum chemistry.
    Harrison, RJ
    Fann, GI
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2002, 223 : U477 - U477