A multi-resolution approach for worm detection and containment

被引:21
|
作者
Sekar, Vyas [1 ]
Xie, Yinglian [1 ]
Reiter, Michael K. [1 ]
Zhang, Hui [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
关键词
D O I
10.1109/DSN.2006.6
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Despite the proliferation of detection and containment techniques in the worm defense literature, simple threshold-based methods remain the most widely deployed and most popular approach among practitioners. This popularity arises out of the simplistic appeal, ease of use, and independence from attack-specific properties such as scanning strategies and signatures. However, such approaches have known limitations: they either fail to detect low-rate attacks or incur very high false positive rates. We propose a multi-resolution approach to enhance the power of threshold-based detection and rate-limiting techniques. Using such an approach we can not only detect fast attacks with low latency, but also discover low-rate attacks - several orders of magnitude less aggressive than today's fast propagating attacks - with low false positive rates. We also outline a multi-resolution rate limiting mechanism for throttling the number of new connections a host can make, to contain the spread of worms. Our trace analysis and simulation experiments demonstrate the benefits of a multiresolution approach for worm defense.
引用
收藏
页码:189 / 198
页数:10
相关论文
共 50 条
  • [41] Multi-resolution Edge Detection with Edge Pattern Analysis
    Jiang, Bo
    MULTIMEDIA CONTENT AND MOBILE DEVICES, 2013, 8667
  • [42] Image Splicing Detection Using Multi-resolution Histogram
    Liu, Jin
    Ling, Hefei
    Zou, Fuhao
    Lu, Zhengding
    ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2009, 2009, 5879 : 858 - 866
  • [43] Lung Nodule Detection Using Multi-Resolution Analysis
    Assefa, Mickias
    Faye, Ibrahima
    Malik, Aamir Saeed
    Shoaib, Muhammad
    2013 ICME INTERNATIONAL CONFERENCE ON COMPLEX MEDICAL ENGINEERING (CME), 2013, : 457 - 461
  • [44] Multi-Resolution Grids in Earthquake Forecasting: The Quadtree Approach
    Asim, Khawaja M.
    Schorlemmer, Danijel
    Hainzl, Sebastian
    Iturrieta, Pablo
    Savran, William H.
    Bayona, Jose A.
    Werner, Maximilian J.
    BULLETIN OF THE SEISMOLOGICAL SOCIETY OF AMERICA, 2023, 113 (01) : 333 - 347
  • [45] Specification of multi-resolution modeling space for multi-resolution system simulation
    Hong, Su-Youn
    Kim, Tag Gon
    SIMULATION-TRANSACTIONS OF THE SOCIETY FOR MODELING AND SIMULATION INTERNATIONAL, 2013, 89 (01): : 28 - 40
  • [46] Multi-resolution local histogram analysis for edge detection
    Aggoun, A.
    Khallil, M.
    2007 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOLS 1-7, 2007, : 1173 - 1176
  • [47] ATTRIBUTE NOISE DETECTION USING MULTI-RESOLUTION ANALYSIS
    Folleco, Andres
    Khoshgoftaar, Taghi
    INTERNATIONAL JOURNAL OF RELIABILITY QUALITY & SAFETY ENGINEERING, 2006, 13 (03): : 267 - 288
  • [48] Improvement to Multi-resolution Collective Detection in GNSS Receivers
    Li, Li
    Cheong, Joon Wayn
    Wu, Jinghui
    Dempster, Andrew G.
    JOURNAL OF NAVIGATION, 2014, 67 (02): : 277 - 293
  • [49] Multi-resolution approach to identification of recurring signal patterns
    Kamarthi, Sagar V.
    Zeid, Ibrahim
    Subramaniam, Lakshmanan
    WAVELET APPLICATIONS IN INDUSTRIAL PROCESSING IV, 2006, 6383
  • [50] A Multi-Resolution Approach for Color Correction of Textured Meshes
    Rouhani, Mohammad
    Fradet, Matthieu
    Baillard, Caroline
    2018 INTERNATIONAL CONFERENCE ON 3D VISION (3DV), 2018, : 71 - 78