TY - GEN
T1 - A distributed detection of hit-list worms
AU - Kawaguchi, Nobutaka
AU - Shigeno, Hiroshi
AU - Okada, Kenichi
PY - 2008/9/12
Y1 - 2008/9/12
N2 - In this paper, we propose d-ACTM/VT, a network based worm detection method that effectively detects hit-list worms. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. d-ACTM/VT addresses this problem by aggregating the divided trees as a tree named Virtual AC tree in a distributed manner and utilizes it for detection. Simulation result shows d-ACTM/VT reduces the number of infected hosts by 20% compared to d-ACTM.
AB - In this paper, we propose d-ACTM/VT, a network based worm detection method that effectively detects hit-list worms. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. d-ACTM/VT addresses this problem by aggregating the divided trees as a tree named Virtual AC tree in a distributed manner and utilizes it for detection. Simulation result shows d-ACTM/VT reduces the number of infected hosts by 20% compared to d-ACTM.
UR - http://www.scopus.com/inward/record.url?scp=51249105542&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=51249105542&partnerID=8YFLogxK
U2 - 10.1109/ICC.2008.303
DO - 10.1109/ICC.2008.303
M3 - Conference contribution
AN - SCOPUS:51249105542
SN - 9781424420742
T3 - IEEE International Conference on Communications
SP - 1566
EP - 1572
BT - ICC 2008 - IEEE International Conference on Communications, Proceedings
T2 - IEEE International Conference on Communications, ICC 2008
Y2 - 19 May 2008 through 23 May 2008
ER -