首页    期刊浏览 2024年11月26日 星期二
登录注册

文章基本信息

  • 标题:Limiting Self-Propagating Malware Based on Connection Failure Behavior
  • 本地全文:下载
  • 作者:Yian Zhou ; You Zhou ; Shigang Chen
  • 期刊名称:Computer Science & Information Technology
  • 电子版ISSN:2231-5403
  • 出版年度:2015
  • 卷号:5
  • 期号:16
  • 页码:99-114
  • DOI:10.5121/csit.2015.51609
  • 出版社:Academy & Industry Research Collaboration Center (AIRCC)
  • 摘要:Self-propagating malware (e.g., an Internet worm) exploits security loopholes in software toinfect servers and then use them to scan the Internet for more vulnerable servers. While themechanisms of worm infection and their propagation models are well understood, defenseagainst worms remains an open problem. One branch of defense research investigates thebehavioral difference between worm-infected hosts and normal hosts to set them apart. Oneparticular observation is that a worm-infected host, which scans the Internet with randomlyselected addresses, has a much higher connection-failure rate than a normal host. Rate-limitalgorithms have been proposed to control the spread of worms by traffic shaping based onconnection failure rate. However, these rate-limit algorithms can work properly only if it ispossible to measure failure rates of individual hosts efficiently and accurately. This paper pointsout a serious problem in the prior method and proposes a new solution based on a highlyefficient double-bitmap data structure, which places only a small memory footprint on therouters, while providing good measurement of connection failure rates whose accuracy can betuned by system parameters.
  • 关键词:Self-propagating Malware; Connection Failure Behavior; Rate Limitation; Shared Bitmap
国家哲学社会科学文献中心版权所有