Anti-Virus White Papers

An OS Independent Heuristics-Based Worm-Containment System

Overview This paper presents an operating system independent and tamper-resistant worm-containment end-system. This system continuously observes outgoing network traffic over a finite-duration traffic window, and using heuristic rules executing in a secondary environment, detects infections. It automatically quarantines the infected host to stop further spread of the worm. The paper presents four heuristic rules, and using network traffic traces collected from an enterprise network demonstrate that a port/protocol-tuned version of the heuristic provides lowest false-positives rate for different settings. Using simulations, the paper further evaluates the effectiveness of this heuristic in containing the spread of a worm in a medium-sized network.

Further White Paper Details
PublisherIntel File FormatPDF
Date PublishedAugust 2005
FormatWhite Papers   
Topics

Quick Sitemap Links: