Darknet-Based Inference of Internet Worm Temporal Characteristics

作者: Qian Wang , Zesheng Chen , Chao Chen

DOI: 10.1109/TIFS.2011.2161288

关键词:

摘要: Internet worm attacks pose a significant threat to network security and management. In this work, we coin the term tomography as inferring characteristics of worms from observations Darknet or telescopes that monitor routable but unused IP address space. Under framework tomography, attempt infer temporal behaviors, i.e., host infection time sequence, thus pinpoint patient zero initially infected hosts. Specifically, apply statistical estimation techniques propose method moments, maximum likelihood, linear regression estimators. We show analytically empirically our proposed estimators can better than naive estimator has been used in previous work. also demonstrate be applied using different scanning strategies such random localized scanning.

参考文章(35)
David Moore, Colleen Shannon, Geoffrey M Voelker, Stefan Savage, Network Telescopes: Technical Report ,(2004)
Raj Jain, The art of computer systems performance analysis Int. CMG Conference. pp. 1233- 1236 ,(1991)
Mary Vernon, Jason Franklin, John Bethencourt, Mapping internet sensors with probe response attacks usenix security symposium. pp. 13- 13 ,(2005)
Michael Bailey, Evan Cooke, Farnam Jahanian, Jose Nazario, David Watson, None, The Internet Motion Sensor - A Distributed Blackhole Monitoring System. network and distributed system security symposium. ,(2005)
Sarma Vangala, Kevin A. Kwiat, Lixin Gao, Jiang Wu, An Effective Architecture and Algorithm for Detecting Worms with Various Scan. network and distributed system security symposium. ,(2004)
Jaeyeon Jung, V. Paxson, A.W. Berger, H. Balakrishnan, Fast portscan detection using sequential hypothesis testing ieee symposium on security and privacy. pp. 211- 225 ,(2004) , 10.1109/SECPRI.2004.1301325
Vern Paxson, Stuart Staniford, Nicholas Weaver, Very fast containment of scanning worms usenix security symposium. pp. 3- 3 ,(2004)
Sailes K. Sengijpta, Fundamentals of Statistical Signal Processing: Estimation Theory Technometrics. ,vol. 37, pp. 465- 466 ,(1995) , 10.1080/00401706.1995.10484391