• DocumentCode
    1542133
  • Title

    On the Characteristics of the Worm Infection Family Tree

  • Author

    Wang, Qian ; Chen, Zesheng ; Chen, Chao

  • Author_Institution
    Microsoft Corp., Redmond, WA, USA
  • Volume
    7
  • Issue
    5
  • fYear
    2012
  • Firstpage
    1614
  • Lastpage
    1627
  • Abstract
    Internet worm infection continues to be one of top security threats and has been widely used by botnets to recruit new bots. In this work, we attempt to quantify the infection ability of individual hosts and reveal the key characteristics of the underlying topology formed by worm infection, i.e., the number of children and the generation of the worm infection family tree. Specifically, we first apply probabilistic modeling methods and a sequential growth model to analyze the infection tree of a wide class of worms. Through both mathematical analysis and simulation, we find that the number of children has asymptotically a geometric distribution with parameter 0.5. As a result, on average half of infected hosts never compromise any vulnerable host, over 98% of infected hosts have no more than five children, and a small portion of infected hosts have a large number of children. We also discover that the generation follows closely a Poisson distribution and the average path length of the worm infection family tree increases approximately logarithmically with the total number of infected hosts. Next, we study the infection structure of localized-scanning and permutation-scanning worms through simulation and surprisingly find that the above observations also apply to these worms. Finally, we apply our findings to evaluate bot assessment strategies for forensic analysis after a worm tree has been formed.
  • Keywords
    Internet; Poisson distribution; computer network security; geometry; invasive software; telecommunication network topology; trees (mathematics); Internet worm infection family tree characteristics; Poisson distribution; approximate-logarithmic average path length; asymptotic geometric distribution; bot assessment strategies; botnets; children; forensic analysis; host infection ability quantification; localized-scanning worms; mathematical analysis; permutation-scanning worms; probabilistic modeling methods; security threats; sequential growth model; simulations; vulnerable host; worm infection topology; Analytical models; Grippers; Internet; Joints; Mathematical model; Measurement; Peer to peer computing; Botnet; detection; probabilistic modeling; simulation; topology; worm infection family tree;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2012.2204981
  • Filename
    6218774