Skip to main content
Journal cover image

Worm origin identification using random moonwalks

Publication ,  Conference
Xie, Y; Sekar, V; Maltz, DA; Reiter, MK; Zhang, H
Published in: Proceedings - IEEE Symposium on Security and Privacy
November 10, 2005

We propose a novel technique that can determine both the host responsible for originating a propagating worm attack and the set of attack flows that make up the initial stages of the attack tree via which the worm infected successive generations of victims. We argue that knowledge of both is important for combating worms: knowledge of the origin supports law enforcement, and knowledge of the causal flows that advance the attack supports diagnosis of how network defenses were breached. Our technique exploits the "wide tree" shape of a worm propagation emanating from the source by performing random "moonwalks" backward in time along paths of flows. Correlating the repeated walks reveals the initial causal flows, thereby aiding in identifying the source. Using analysis, simulation, and experiments with real world traces, we show how the technique works against both today's fast propagating worms and stealthy worms that attempt to hide their attack flows among background traffic. © 2005 IEEE.

Duke Scholars

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

ISSN

1081-6011

ISBN

0769523390

Publication Date

November 10, 2005

Start / End Page

242 / 256
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Xie, Y., Sekar, V., Maltz, D. A., Reiter, M. K., & Zhang, H. (2005). Worm origin identification using random moonwalks. In Proceedings - IEEE Symposium on Security and Privacy (pp. 242–256). https://doi.org/10.1109/SP.2005.23
Xie, Y., V. Sekar, D. A. Maltz, M. K. Reiter, and H. Zhang. “Worm origin identification using random moonwalks.” In Proceedings - IEEE Symposium on Security and Privacy, 242–56, 2005. https://doi.org/10.1109/SP.2005.23.
Xie Y, Sekar V, Maltz DA, Reiter MK, Zhang H. Worm origin identification using random moonwalks. In: Proceedings - IEEE Symposium on Security and Privacy. 2005. p. 242–56.
Xie, Y., et al. “Worm origin identification using random moonwalks.” Proceedings - IEEE Symposium on Security and Privacy, 2005, pp. 242–56. Scopus, doi:10.1109/SP.2005.23.
Xie Y, Sekar V, Maltz DA, Reiter MK, Zhang H. Worm origin identification using random moonwalks. Proceedings - IEEE Symposium on Security and Privacy. 2005. p. 242–256.
Journal cover image

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

ISSN

1081-6011

ISBN

0769523390

Publication Date

November 10, 2005

Start / End Page

242 / 256