• DocumentCode
    2966854
  • Title

    A framework for real-time worm attack detection and backbone monitoring

  • Author

    Dubendorfer, Thomas ; Wagner, Arno ; Plattner, Bernhard

  • Author_Institution
    Lab. of Comput. Eng. & Networks, Swiss Fed. Inst. of Technol., Zurich, Switzerland
  • fYear
    2005
  • fDate
    3-4 Nov. 2005
  • Abstract
    We developed an open source Internet backbone monitoring and traffic analysis framework named UPFrame. It captures UDP NetFlow packets, buffers it in shared memory and feeds it to customised plug-ins. UPFrame is highly tolerant to misbehaving plug-ins and provides a watchdog mechanism for restarting crashed plug-ins. This makes UP-Frame an ideal platform for experiments. It also features a traffic shaper for smoothing incoming traffic bursts. Using this framework, we have investigated IDS-like anomaly detection possibilities for high-speed Internet backbone networks. We have implemented several plug-ins for host behaviour classification, traffic activity pattern recognition, and traffic monitoring. We successfully detected the recent Blaster, Nachi and Witty worm outbreaks in a medium-sized Swiss Internet backbone (AS559) using border router NetFlow data captured in the DDoSVax project. The framework is efficient and robust and can complement traditional intrusion detection systems.
  • Keywords
    Internet; monitoring; telecommunication security; telecommunication traffic; Blaster outbreaks; Internet backbone monitoring; Nachi outbreaks; UDP NetFlow packets; UPFrame; Witty worm outbreaks; intrusion detection systems; medium-sized Swiss Internet backbone; real-time worm attack detection; traffic activity pattern recognition; traffic analysis; traffic monitoring; watchdog mechanism; Computer crashes; Feeds; IP networks; Internet; Monitoring; Pattern recognition; Robustness; Smoothing methods; Spine; Telecommunication traffic; Blaster; Nachi; NetFlow; UPFrame; Witty; anomaly detection; backbone; framework; host behaviour; online analysis; plug-in; worm outbreak;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Critical Infrastructure Protection, First IEEE International Workshop on
  • Print_ISBN
    0-7695-2426-5
  • Type

    conf

  • DOI
    10.1109/IWCIP.2005.2
  • Filename
    1572282