DocumentCode
2813612
Title
Dynamic control of worm propagation
Author
Dantu, Ram ; Cangussu, João ; Yelimeli, Arun
Author_Institution
North Texas Univ., Denton, TX, USA
Volume
1
fYear
2004
fDate
5-7 April 2004
Firstpage
419
Abstract
In a computer network, network security is accomplished using elements like firewalls, hosts, servers, routers, intrusion detection systems, and honey pots. These network elements need to know the nature or anomaly of the worm in priori to detect the attack. Modern day viruses like Code red, Sapphire and Nimda spread very fast. For example, Sapphire can double its size and infect more than 90% of the vulnerable hosts within 10 minutes. Therefore it is impractical if not impossible for human mediated responses to these modern day fast spreading viruses. Several epidemic studies show that automatic tracking of resource usage and control is an effective method in containing the damage. In this paper we propose a state space feedback control model to detect and control the spread of these viruses by measuring the number of connections an infected host makes. The objective of the mechanism is to slow down the spreading velocity of a worm by controlling (delaying) the total number of connections made by an infected host. As expected, the model showed that the sooner the infection is detected the faster the reduction of the spreading velocity. Additionally, the deployment of a controller at different levels (host and firewall) has shown to be very promising.
Keywords
authorisation; computer networks; feedback; invasive software; system monitoring; telecommunication security; Code red; Nimda; Sapphire; attack detection; automatic tracking; computer network; computer viruses; dynamic control; firewalls; infected host; intrusion detection systems; network elements; network security; resource usage; routers; servers; spreading velocity; state space feedback control model; worm propagation; Automatic control; Computer networks; Computer security; Computer viruses; Computer worms; Humans; Intrusion detection; Network servers; State-space methods; Viruses (medical);
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
Print_ISBN
0-7695-2108-8
Type
conf
DOI
10.1109/ITCC.2004.1286491
Filename
1286491
Link To Document