Anda belum login :: 30 Apr 2025 14:53 WIB
Home
|
Logon
Hidden
»
Administration
»
Collection Detail
Detail
Enhancing SWORD To Detect Zero-Day-Worm-Infected Hosts
Oleh:
Stafford, Shad
;
Li, Jun
;
Ehrenkranz, Toby
Jenis:
Article from Journal - ilmiah internasional
Dalam koleksi:
Simulation vol. 83 no. 2 (Feb. 2007)
,
page 199-212.
Topik:
Internet worms
;
worm detection
;
net-work security
;
host infection
Fulltext:
199.pdf
(334.54KB)
Isi artikel
Once a host is infected by an Internet worm, prompt action must be taken before that host does more harm to its local network and the rest of the Internet. It is therefore critical to quickly detect that a worm has infected a host. In this paper, we enhance our SWORD system to allow for the detection of infected hosts and evaluate its performance. This enhanced version of SWORD inherits the advantages of the original SWORD: it does not rely on inspecting traffic payloads to search for worm byte patterns or setting up a honeypot to lure worm traffic. Furthermore, while acting as a host-level detection system, it runs at a network’s gateway and stays transparent to individual hosts. We show that our enhanced SWORD system is able to quickly and accurately detect if a host is infected by a zero-day worm. Furthermore, the detection is shown to be effective against worms of different types and speeds, including polymorphic worms
Opini Anda
Klik untuk menuliskan opini Anda tentang koleksi ini!
Kembali
Process time: 0 second(s)