首页> 外文会议>4th ACM symposium on information, computer and communications security 2009 >An Integrated Approach to Detection of Fast and Slow Scanning Worms
【24h】

An Integrated Approach to Detection of Fast and Slow Scanning Worms

机译:一种用于检测快速和慢速扫描蠕虫的集成方法

获取原文
获取原文并翻译 | 示例

摘要

The propagation speed of fast scanning worms and the stealthy nature of slow scanning worms present unique challenges to intrusion detection. Typically, techniques optimized for detection of fast scanning worms fail to detect slow scanning worms, and vice versa. In practice, there is interest in developing an integrated approach to detecting both classes of worms. In this paper, we propose and analyze a unique integrated detection approach capable of detecting and identifying traffic flow(s) responsible for simultaneous fast and slow scanning malicious worm attacks. The approach uses a combination of evidence from distributed host-based anomaly detectors, a self-adapting profiler and Bayesian inference from network heuristics to detect intrusion activity due to both fast and slow scanning worms. We assume that the extreme nature of fast scanning worm epidemics make them well suited for extreme value theory and use sample mean excess function to determine appropriate thresholds for detection of such worms. Random scanning worm behavior is considered in analyzing the stochastic time intervals that affect behavior of the detection technique. Based on the analysis, a probability model for worm detection interval using the detection scheme was developed. Simulations are used to validate our assumptions and analysis.
机译:快速扫描蠕虫的传播速度和慢速扫描蠕虫的隐秘性质对入侵检测提出了独特的挑战。通常,为检测快速扫描蠕虫而优化的技术无法检测到慢速扫描蠕虫,反之亦然。在实践中,有兴趣开发一种用于检测两种蠕虫的集成方法。在本文中,我们提出并分析了一种独特的集成检测方法,该方法能够检测和识别负责同时快速和缓慢扫描恶意蠕虫攻击的流量。该方法结合了来自基于主机的分布式异常检测器的证据,自适应分析器以及来自网络启发式方法的贝叶斯推断,以检测由于快慢蠕虫引起的入侵活动。我们假设快速扫描蠕虫流行病的极端性质使其非常适合极值理论,并使用样本均值过剩函数确定检测此类蠕虫的适当阈值。在分析影响检测技术行为的随机时间间隔时,应考虑使用随机扫描蠕虫行为。在此基础上,建立了利用该检测方案的蠕虫检测间隔概率模型。仿真用于验证我们的假设和分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号