DocumentCode
2966854
Title
A framework for real-time worm attack detection and backbone monitoring
Author
Dubendorfer, Thomas ; Wagner, Arno ; Plattner, Bernhard
Author_Institution
Lab. of Comput. Eng. & Networks, Swiss Fed. Inst. of Technol., Zurich, Switzerland
fYear
2005
fDate
3-4 Nov. 2005
Abstract
We developed an open source Internet backbone monitoring and traffic analysis framework named UPFrame. It captures UDP NetFlow packets, buffers it in shared memory and feeds it to customised plug-ins. UPFrame is highly tolerant to misbehaving plug-ins and provides a watchdog mechanism for restarting crashed plug-ins. This makes UP-Frame an ideal platform for experiments. It also features a traffic shaper for smoothing incoming traffic bursts. Using this framework, we have investigated IDS-like anomaly detection possibilities for high-speed Internet backbone networks. We have implemented several plug-ins for host behaviour classification, traffic activity pattern recognition, and traffic monitoring. We successfully detected the recent Blaster, Nachi and Witty worm outbreaks in a medium-sized Swiss Internet backbone (AS559) using border router NetFlow data captured in the DDoSVax project. The framework is efficient and robust and can complement traditional intrusion detection systems.
Keywords
Internet; monitoring; telecommunication security; telecommunication traffic; Blaster outbreaks; Internet backbone monitoring; Nachi outbreaks; UDP NetFlow packets; UPFrame; Witty worm outbreaks; intrusion detection systems; medium-sized Swiss Internet backbone; real-time worm attack detection; traffic activity pattern recognition; traffic analysis; traffic monitoring; watchdog mechanism; Computer crashes; Feeds; IP networks; Internet; Monitoring; Pattern recognition; Robustness; Smoothing methods; Spine; Telecommunication traffic; Blaster; Nachi; NetFlow; UPFrame; Witty; anomaly detection; backbone; framework; host behaviour; online analysis; plug-in; worm outbreak;
fLanguage
English
Publisher
ieee
Conference_Titel
Critical Infrastructure Protection, First IEEE International Workshop on
Print_ISBN
0-7695-2426-5
Type
conf
DOI
10.1109/IWCIP.2005.2
Filename
1572282
Link To Document