Firewalls White Papers
Adaptive Detection of Worms/Viruses in Firewalls
Overview This paper seeks to answer the question: "How to detect worms/viruses, which are replicated via emails, at the level of a firewall without cooperation with an anti-virus server?" All packets pass through firewalls and only firewalls are able to prevent packets from entering the network. The motivation is to reduce risk through preventing malicious packets (e.g., worms/viruses) from entering the secure network. It present the firewall model and address how to detect worms/viruses based on protocol sanity, probabilistic estimation of maliciousness, and patterns of packets.
| Publisher | University of Fribourg | File Format | |
|---|---|---|---|
| Date Published | February 2005 | ||
| Format | White Papers | ||
| Topics | |||


