DocumentCode :
3516568
Title :
Verme: Worm containment in overlay networks
Author :
Freitas, Filipe ; Marques, Edgar ; Rodrigues, Rodrigo ; Ribeiro, Carlos ; Ferreira, Paulo ; Rodrigues, Luís
Author_Institution :
INESC-ID, Tech. Univ. of Lisbon, Lisbon, Portugal
fYear :
2009
fDate :
June 29 2009-July 2 2009
Firstpage :
155
Lastpage :
164
Abstract :
Topological worms, such as those that propagate by following links in an overlay network, have the potential to spread faster than traditional random scanning worms because they have knowledge of a subset of the overlay nodes, and choose these nodes to propagate themselves; and also because they can avoid traditional detection mechanisms. Furthermore, this worm propagation strategy is likely to become prevalent as the deployment of networks with a sparse address space, such as IPv6, makes the traditional random scanning strategy futile. We present a novel approach for containing topological worms based on the fact that some overlay nodes may not have common vulnerabilities, due to their platform diversity. By reorganizing the overlay graph, it is possible to contain topological worms in small islands of nodes with common vulnerabilities that only have knowledge of themselves or nodes running on distinct platforms. We also present the design of Verme, a peer-to-peer overlay based on Chord that follows this approach, and VerDi, a DHT layer built on top of the Verme routing overlay. Simulations show that Verme and VerDi have a low overhead when compared to Chord´s corresponding layers, and that our new overlay design helps containing, or at least slowing down the propagation of topological worms.
Keywords :
invasive software; peer-to-peer computing; telecommunication security; DHT layer; VerDi; Verme; peer-to-peer overlay network; topological worms; worm propagation strategy; Analytical models; Delay effects; Internet; Network topology; Peer to peer computing; Probes; Routing; Software systems; Surveillance; Viruses (medical);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
Conference_Location :
Lisbon
Print_ISBN :
978-1-4244-4422-9
Electronic_ISBN :
978-1-4244-4421-2
Type :
conf
DOI :
10.1109/DSN.2009.5270341
Filename :
5270341
Link To Document :
بازگشت