Skip to main content

A multi-resolution approach for worm detection and containment

Publication ,  Conference
Sekar, V; Yinglian, X; Reiter, MK; Hui, Z
Published in: Proceedings of the International Conference on Dependable Systems and Networks
December 22, 2006

Despite the proliferation of detection and containment techniques in the worm, defense literature, simple threshold-based methods remain the most widely deployed and most popular approach among practitioners. This popularity arises out of the simplistic appeal, ease of use, and independence from attack-specific properties such as scanning strategies and signatures. However, such approaches have known limitations: they either fail to detect low-rate attacks or incur very high false positive rates. We propose a multi-resolution approach to enhance the power of threshold-based detection and rate-limiting techniques. Using such an approach we can not only detect fast attacks with low latency, but also discover low-rate attacks - several orders of magnitude less aggressive than today's fast propagating attacks - with low false positive rates. We also outline a multi-resolution rate limiting mechanism for throttling the number of new connections a host can make, to contain the spread of worms. Our trace analysis and simulation experiments demonstrate the benefits of a multiresolution approach for worm defense. © 2006 IEEE.

Duke Scholars

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

December 22, 2006

Volume

2006

Start / End Page

189 / 198
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Sekar, V., Yinglian, X., Reiter, M. K., & Hui, Z. (2006). A multi-resolution approach for worm detection and containment. In Proceedings of the International Conference on Dependable Systems and Networks (Vol. 2006, pp. 189–198). https://doi.org/10.1109/DSN.2006.6
Sekar, V., X. Yinglian, M. K. Reiter, and Z. Hui. “A multi-resolution approach for worm detection and containment.” In Proceedings of the International Conference on Dependable Systems and Networks, 2006:189–98, 2006. https://doi.org/10.1109/DSN.2006.6.
Sekar V, Yinglian X, Reiter MK, Hui Z. A multi-resolution approach for worm detection and containment. In: Proceedings of the International Conference on Dependable Systems and Networks. 2006. p. 189–98.
Sekar, V., et al. “A multi-resolution approach for worm detection and containment.” Proceedings of the International Conference on Dependable Systems and Networks, vol. 2006, 2006, pp. 189–98. Scopus, doi:10.1109/DSN.2006.6.
Sekar V, Yinglian X, Reiter MK, Hui Z. A multi-resolution approach for worm detection and containment. Proceedings of the International Conference on Dependable Systems and Networks. 2006. p. 189–198.

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

December 22, 2006

Volume

2006

Start / End Page

189 / 198