Anti-Virus White Papers
An OS Independent Heuristics-Based Worm-Containment System
Overview This paper presents an operating system independent and tamper-resistant worm-containment end-system. This system continuously observes outgoing network traffic over a finite-duration traffic window, and using heuristic rules executing in a secondary environment, detects infections. It automatically quarantines the infected host to stop further spread of the worm. The paper presents four heuristic rules, and using network traffic traces collected from an enterprise network demonstrate that a port/protocol-tuned version of the heuristic provides lowest false-positives rate for different settings. Using simulations, the paper further evaluates the effectiveness of this heuristic in containing the spread of a worm in a medium-sized network.
| Publisher | Intel | File Format | |
|---|---|---|---|
| Date Published | August 2005 | ||
| Format | White Papers | ||
| Topics | |||



