Network Security White Papers

A Distributed Host-Based Worm Detection System

Overview This paper present a method for detecting large-scale worm attacks using only end-host detectors. These detectors propagate and aggregate alerts to cooperating partners to detect large-scale distributed attacks in progress. The properties of the host-based detectors may in fact be relatively poor in isolation but when taken collectively result in a high-quality distributed worm detector. A cooperative alert sharing protocol coupled with distributed sequential hypothesis testing is implemented to generate global alarms about distributed attacks. The system's response is evaluated in the presence of a variety of false alarm conditions and in the presence of an Internet worm attack. This evaluation is conducted with agents on the Emulab and DETER emulated testbeds using real operating systems and computing platforms.

Further White Paper Details
PublisherAssociation for Computing Machinery File FormatPDF
Date PublishedSeptember 2006
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Danone on health kick with Itil

Danone on health kick with Itil

Case study: Food company making IT easier to manage more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: