Title :
PAIDS: A Proximity-Assisted Intrusion Detection System for Unidentified Worms
Author :
Zhuang, Zhenyun ; Li, Ying ; Chen, Zesheng
Author_Institution :
Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
Abstract :
The wide spread of worms poses serious challenges to today´s Internet.Various IDSes (intrusion detection systems) have been proposed to identify or prevent such spread. These IDSes can be largely classified as signature-based or anomaly-based ones depending on what type of knowledge the system knows. Signature-based IDSes are unable to detect the outbreak of new and unidentified worms when the worms´ characteristic patterns are unknown. In addition, new worms are often sufficiently intelligent to hide their activities and evade anomaly detection. Moreover, modern worms tend to spread more quickly, and the outbreak period lasts in the order of hours or even minutes. Such characteristics render existing detection mechanisms less effective.In this work, we consider the drawbacks of current detection approaches and propose PAIDS, a proximity-assisted IDS approach for identifying the outbreak of unknown worms. PAIDS does not rely on signatures.Instead, it takes advantage of the proximity information of compromised hosts. PAIDS operates on an orthogonal dimension with existing IDS approaches and can thus work collaboratively with existing IDSes to achieve better performance. We test the effectiveness of PAIDS with trace-driven simulations and show that PAIDS has a high detection rate and a low false positive rate.
Keywords :
Internet; digital signatures; invasive software; Internet; PAIDS; anomaly detection; proximity-assisted intrusion detection system; signature-based scheme; unidentified worm; Application software; Collaborative work; Computer applications; Computer worms; Educational institutions; Failure analysis; Impedance; Internet; Intrusion detection; Pattern analysis; Intrusion Detection System; Proximity; Worm;
Conference_Titel :
Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
Conference_Location :
Seattle, WA
Print_ISBN :
978-0-7695-3726-9
DOI :
10.1109/COMPSAC.2009.59