首页    期刊浏览 2024年12月03日 星期二
登录注册

文章基本信息

  • 标题:Hit-list Worm Detection Using Distributed Sliding Window
  • 本地全文:下载
  • 作者:Nobutaka Kawaguchi ; Hiroshi Shigeno ; Ken'ichi Okada
  • 期刊名称:Information and Media Technologies
  • 电子版ISSN:1881-0896
  • 出版年度:2011
  • 卷号:6
  • 期号:2
  • 页码:660-669
  • DOI:10.11185/imt.6.660
  • 出版社:Information and Media Technologies Editorial Board
  • 摘要:In this paper, we propose a new distributed hit-list worm detection method: the Anomaly Connection Tree Method with Distributed Sliding Window (ACTM-DSW). ACTM-DSW employs multiple distributed network Intrusion Detection Systems (IDSs), each of which monitors a small portion of an enterprise network. In ACTM-DSW, worm propagation trees are detected by using a sliding time window. More precisely, the distributed IDSs in ACTM-DSW cooperatively detect tree structures composed of the worm's infection connections that have been made within a time window. Through computer-based simulations, we demonstrate that ACTM-DSW outperforms an existing distributed worm detection method, called d-ACTM/VT, for detecting worms whose infection intervals are not constant, but rather have an exponential or uniform distribution. In addition, we implement the distributed IDSs on Xen, a virtual machine environment, and demonstrate the feasibility of the proposed method experimentally.
国家哲学社会科学文献中心版权所有