作者: Guofei Gu , M. Sharif , Xinzhou Qin , D. Dagon , Wenke Lee
DOI: 10.1109/CSAC.2004.51
关键词:
摘要: Worm detection systems have traditionally focused on global strategies. In the absence of a worm system, we examine effectiveness local and response This paper makes three contributions: (1) propose simple two-phase victim algorithm, DSC (Destination-Source Correlation), based behavior in terms both infection pattern scanning pattern. can detect zero-day worms with high rate very low false positive rate. (2) We demonstrate early warning information. For example, occurs 0.19% all vulnerable hosts Internet when using /12 monitored network. (3) Based information, investigate evaluate an automatic real-time slowing down propagation. are general results, not specific to certain algorithm like DSC. analytical models packet-level network simulator experiments.