Sciweavers

RAID
2004
Springer

Fast Detection of Scanning Worm Infections

13 years 9 months ago
Fast Detection of Scanning Worm Infections
Worm detection and response systems must act quickly to identify and quarantine scanning worms, as when left unchecked such worms have been able to infect the majority of vulnerable hosts on the Internet in a matter of minutes [9]. We present a hybrid approach to detecting scanning worms that integrates significant improvements we have made to two existing techniques: sequential hypothesis testing and connection rate limiting. Our results show that this two-pronged approach successfully restricts the number of scans that a worm can complete, is highly effective, and has a low false alarm rate.
Stuart E. Schechter, Jaeyeon Jung, Arthur W. Berge
Added 02 Jul 2010
Updated 02 Jul 2010
Type Conference
Year 2004
Where RAID
Authors Stuart E. Schechter, Jaeyeon Jung, Arthur W. Berger
Comments (0)