4.6 Article

On the Detection of Smart, Self-Propagating Internet Worms

期刊

出版社

IEEE COMPUTER SOC
DOI: 10.1109/TDSC.2022.3194127

关键词

Internet worm; smart worm; worm detection; behavior-based worm detection; mirai worm

向作者/读者索取更多资源

Self-propagating worms can quickly infect millions of computers on the Internet. The recent Mirai and WannaCry worms serve as evidence that worm attacks are real, destructive, and persistent. Existing worm detectors have limitations in terms of considering countermeasures from worm authors, addressing inbound worms, and requiring bi-directional traffic. This paper proposes a new worm detector called SWORD, which focuses on the fundamental behavior of worms and overcomes the drawbacks of existing detectors. Experimental results using simulated and real-world worm traffic show that SWORD outperforms existing detectors in detecting both classic and evasive outbound worms, as well as inbound worms.
Self-propagating worms can infect millions of computers on the Internet in just several minutes. As witnessed by the recent Mirai and WannaCry worms, worm attacks are real, destructive, and continue to persist. Although many worm detectors exist, most that we studied suffer from three drawbacks: none systematically consider countermeasures from worm authors, potentially causing low effectiveness against evasive worms; all focus on outbound worms leaving a network, leaving their efficacy against inbound worms entering a network unanswered; and many require bi-directional traffic to detect worms, making their placement on the Internet inflexible. We therefore revisit worm detection in this paper, while avoiding the aforementioned drawbacks of existing work. We describe our design of SWORD, a new worm detector that focuses on the fundamental behavior of worms. It includes two complementary modules to monitor connections from and to a protected network, with one module monitoring burst durations and the other ensuring quiescent periods. Via extensive experiments using both simulated worm traffic and a real-world Mirai worm trace, we demonstrate that SWORD is superior to existing detectors at not only detecting both classic and evasive outbound worms, but also inbound worms, especially those that are superspreading or surreptitious.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据