• DocumentCode
    474878
  • Title

    WormTerminator

  • Author

    Songqing Chen ; Xinyuan Wang ; Lei Liu ; Xinwen Zhang ; Zhao Zhang

  • Author_Institution
    Dept. of Comput. Sci., George Mason Univ., Fairfax, VA
  • fYear
    2006
  • fDate
    3-5 Dec. 2006
  • Firstpage
    173
  • Lastpage
    182
  • Abstract
    The fast spreading worm is becoming one of the most serious threats to today´s networked information systems. A fast spreading worm could infect hundreds of thousands of hosts within a few minutes. In order to stop a fast spreading worm, we need the capability to detect and contain worms automatically in real-time. While signature based worm detection and containment are effective in detecting and containing known worms, they are inherently ineffective against previously unknown worms and polymorphic worms. Existing traffic anomaly pattern based approaches have the potential to detect and/or contain previously unknown and polymorphic worms, but they either impose too much constraint on normal traffic or allow too much infectious worm traffic to go out to the Internet before an unknown or polymorphic worm can be detected. In this paper, we present WormTerminator, which can detect and completely contain, at least in theory, almost all fast spreading worms in real-time while blocking virtually no normal traffic. WormTerminator detects and contains the fast spreading worm based on its denning characteristic - a fast spreading worm will start to infect others as soon as it successfully infects one host. WormTerminator also exploits the observation that a fast spreading worm keeps exploiting the same set of vulnerabilities when infecting new machines. To prove the concept, we have implemented a prototype of WormTerminator and have examined its effectiveness against the real Internet worm Linux/Slapper.
  • Keywords
    Internet; invasive software; telecommunication security; Internet; WormTerminator; polymorphic fast spreading worm; traffic anomaly pattern based approach; Computer science; Computer worms; Information security; Information systems; Internet; Invasive software; Linux; Permission; Prototypes; Software engineering; polymorphic worms; virtual machine; worm containment; wormterminator; zero-day worms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Architecture for Networking and Communications systems, 2006. ANCS 2006. ACM/IEEE Symposium on
  • Conference_Location
    San Jose, CA
  • Print_ISBN
    978-1-59593-580-9
  • Type

    conf

  • Filename
    4579535