Security Management White Papers

Efficient Quarantining of Scanning Worms: Optimal Detection and Coordination

Overview Current generation worms have caused considerable damage, despite their use of unsophisticated scanning strategies for detecting vulnerable hosts. A number of adaptive techniques have been proposed for quarantining hosts whose behaviour is deemed suspicious. Such techniques have been proven to be effective against fast scanning worms. However, worms could evade detection by being less aggressive. This paper considers the interplay between worm strategies and detection techniques, which can be described in game-theoretic terms. The authors use epidemiological modelling to characterise the outcome of the game (the pay-off function), as a function of the strategies of the worm and the detector. This paper designs detection rules that are optimal against scanning worms with known characteristics.

Further White Paper Details
PublisherMicrosoft File FormatPDF
Date PublishedJanuary 2006
FormatWhite Papers   
Topics

Quick Sitemap Links: