Firewalls White Papers

Adaptive Detection of Worms/Viruses in Firewalls

Overview This paper seeks to answer the question: "How to detect worms/viruses, which are replicated via emails, at the level of a firewall without cooperation with an anti-virus server?" All packets pass through firewalls and only firewalls are able to prevent packets from entering the network. The motivation is to reduce risk through preventing malicious packets (e.g., worms/viruses) from entering the secure network. It present the firewall model and address how to detect worms/viruses based on protocol sanity, probabilistic estimation of maliciousness, and patterns of packets.

Further White Paper Details
PublisherUniversity of Fribourg File FormatPDF
Date PublishedFebruary 2005
FormatWhite Papers   
Topics

Quick Sitemap Links: