作者: Jon Crowcroft , Liyong Tang , Eng Keong Lua , Ruichuan Chen , Zhong Chen
DOI:
关键词:
摘要: Active Peer-to-Peer (P2P) worms present serious threats to the global Internet by exploiting popular P2P applications perform rapid topological self-propagation. pose more deadly than normal scanning because they do not exhibit easily detectable anomalies, thus many existing defenses are no longer effective. We propose an immunity system with Phagocytes --- a small subset of elected hosts that immune high probability and specialized in finding "eating" overlay. The will monitor their managed hosts' connection patterns traffic volume attempt detect active worm attacks. Once detected, local isolation, alert propagation software patching take place for containment. further provide access control filtering mechanisms communication establishment between internal overlay external hosts. We design novel adaptive interaction-based computational puzzle scheme at restrain attacking overlay, without influencing legitimate experiences significantly. implement prototype system, evaluate its performance based on realistic massive-scale network traces. evaluation results illustrate our capable achieving total defense against worms.