• DocumentCode
    1122551
  • Title

    A survey of internet worm detection and containment

  • Author

    Pele Li ; Salour, M. ; Xiao Su

  • Author_Institution
    San Jose State Univ., San Jose, CA
  • Volume
    10
  • Issue
    1
  • fYear
    2008
  • Firstpage
    20
  • Lastpage
    35
  • Abstract
    Self-duplicating, self-propagating malicious codes known as computer worms spread themselves without any human interaction and launch the most destructive attacks against computer networks. At the same time, being fully automated makes their behavior repetitious and predictable. This article presents a survey and comparison of Internet worm detection and containment schemes. We first identify worm characteristics through their behavior, and then classify worm detection algorithms based on the parameters used in the algorithms. Furthermore, we analyze and compare different detection algorithms with reference to the worm characteristics by identifying the type of worms that can and cannot be detected by these schemes. After detecting the existence of worms, the next step is to contain them. This article explores the current methods used to slow down or stop the spread of worms. The locations to implement detection and containment, as well as the scope of each of these systems/methods, are also explored in depth. Finally, this article points out the remaining challenges of worm detection and future research directions.
  • Keywords
    Internet; invasive software; Internet worm detection; computer networks; containment schemes; human interaction; self-duplicating codes; self-propagating malicious codes; Algorithm design and analysis; Computer networks; Computer security; Computer worms; Detection algorithms; IP networks; Internet; Intrusion detection; Storage area networks;
  • fLanguage
    English
  • Journal_Title
    Communications Surveys & Tutorials, IEEE
  • Publisher
    ieee
  • ISSN
    1553-877X
  • Type

    jour

  • DOI
    10.1109/COMST.2008.4483668
  • Filename
    4483668