• DocumentCode
    459468
  • Title

    An Efficient Signature-Based Approach for Automatic Detection of Internet Worms over Large-Scale Networks

  • Author

    Simkhada, Kumar ; Taleb, Tarik ; Waizumi, Yuji ; Jamalipour, Abbas ; Kato, Nei ; Nemoto, Yoshiaki

  • Author_Institution
    Graduate School of Information Sciences, Tohoku University, Japan. kumar@nemoto.ecei.tohoku.ac.jp
  • Volume
    5
  • fYear
    2006
  • fDate
    38869
  • Firstpage
    2364
  • Lastpage
    2369
  • Abstract
    Internet Worms pose a serious threat to today´s Internet. Signature matching is an important approach to detect worms. However, as most signature development processes are manual, they require significant time. They are thus not efficient in reducing the damage worms may cause. In this paper, an efficient signature-based method is proposed for automatic detection of worms over large-scale networks. In the proposed system, detection is performed in a hierarchical manner. Security managers of local networks collect worm-like or suspicious flows and handle these flows to high-hierarchy metropolitan managers. In response, the latter use this information to generate robust signature. The global manager which lies on top of the hierarchy, multicasts the signature to local managers via metropolitan managers. This enables local managers to detect worms that try to penetrate into their networks. The proposed system is evaluated using an off-line real network traffic that contains traces of worms. Experimental results indicate that the proposed system exhibits high detection rates with low false alarm rates.
  • Keywords
    Communication system traffic control; Computer crime; IP networks; Internet; Large-scale systems; Monitoring; Network topology; Security; Telecommunication traffic; Urban areas;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2006. ICC '06. IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    8164-9547
  • Print_ISBN
    1-4244-0355-3
  • Electronic_ISBN
    8164-9547
  • Type

    conf

  • DOI
    10.1109/ICC.2006.255123
  • Filename
    4024518