DocumentCode
3807219
Title
On the Race of Worms, Alerts, and Patches
Author
Milan Vojnovic;Ayalvadi J. Ganesh
Author_Institution
Microsoft Res. Ltd., Cambridge
Volume
16
Issue
5
fYear
2008
Firstpage
1066
Lastpage
1079
Abstract
We provide an analytical framework for evaluating the performance of automatic patching systems. We use it to quantify the speed of patch or alert dissemination required for worm containment. Motivated by scalability and trust issues, we consider a hierarchical system where network hosts are organized into subnets, each containing a patch server (termed superhost). Patches are disseminated to superhosts through an overlay connecting them and, after verification, to end hosts within subnets. The analytical framework accommodates a variety of overlays through the novel abstraction of a minimum broadcast curve. It also accommodates filtering of scans across subnets. The framework provides quantitative estimates that can guide system designers in dimensioning automatic patching systems. The results are obtained mathematically and verified by simulation.
Keywords
"Broadcasting","Internet","Performance analysis","Scalability","Hierarchical systems","Network servers","Joining processes","Information filtering","Information filters","Humans"
Journal_Title
IEEE/ACM Transactions on Networking
Publisher
ieee
ISSN
1063-6692
Type
jour
DOI
10.1109/TNET.2007.909678
Filename
4455449
Link To Document