d-ACTM: Distributed anomaly connection tree method to detect silent worms

Nobutaka Kawaguchi, Hiroshi Shigeno, Ken Ichi Okada

研究成果: Conference contribution

抄録

This paper proposes a distributed network based worm detection method, d-ACTM, to detect a kind of hit-list worm named Silent worm. The worm propagation behavior in the network is expressed as a tree-like structure composed of the infected hosts and the infection connections. d-ACTM detects the existence of worms by detecting the tree structures composed of anomaly connections in a distributed manner. The sim,ulation result shows that d-ACTM can detect Silent worms before 7% of all vulnerable hosts are infected under the condition where the infection interval is equals to the normal connection interval.

本文言語English
ホスト出版物のタイトル27th IEEE International Performance Computing and Communications Conference, IPCCC 07
ページ510-517
ページ数8
DOI
出版ステータスPublished - 2007 11 27
イベント27th IEEE International Performance Computing and Communications Conference, IPCCC 07 - New Orleans, LA, United States
継続期間: 2007 4 112007 4 13

出版物シリーズ

名前Conference Proceedings of the IEEE International Performance, Computing, and Communications Conference

Other

Other27th IEEE International Performance Computing and Communications Conference, IPCCC 07
CountryUnited States
CityNew Orleans, LA
Period07/4/1107/4/13

ASJC Scopus subject areas

  • Engineering(all)

引用スタイル