• DocumentCode
    2953991
  • Title

    Early containment of worms using dummy addresses and connection trace back

  • Author

    Inaba, Taro ; Kawaguchi, Nobutaka ; Tahara, Shinya ; Shigeno, Hiroshi ; Okada, Ken-ichi

  • Author_Institution
    Fac. of Sci. & Technol., Keio Univ., Yokohama
  • Volume
    2
  • fYear
    2007
  • fDate
    5-7 Dec. 2007
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Most of existing network worms have used address scanning to find vulnerable hosts. Recently, however, worms with more effective propagation strategies have emerged. Among the worms, we focus on the worms that exploit address lists obtained from infected hosts to find other vulnerable hosts effectively. In this paper, we propose a method to detect and contain such worms that try to infect all hosts in an enterprise network. In our method, a detection system inserts some dummy addresses into the address lists of hosts in the network. Then, the system detects the existence of worms when a host tries to open a connection to a dummy address, and then traces back the connection logs to find potentially infected hosts and removes them from the network. Computer simulation results showed our method detected and contained worms with less than 1% infected hosts and less than 5% removed hosts.
  • Keywords
    invasive software; connection trace back; dummy addresses; early worm containment; enterprise network; infected hosts; network worms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Systems, 2007 International Conference on
  • Conference_Location
    Hsinchu
  • ISSN
    1521-9097
  • Print_ISBN
    978-1-4244-1889-3
  • Electronic_ISBN
    1521-9097
  • Type

    conf

  • DOI
    10.1109/ICPADS.2007.4447717
  • Filename
    4447717