A Distributed Detection of Hit-List Worms

Description

In this paper, we propose d-ACTM/VT, a network based worm detection method that effectively detects hit-list worms. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. d-ACTM/VT addresses this problem by aggregating the divided trees as a tree named Virtual AC tree in a distributed manner and utilizes it for detection. Simulation result shows d-ACTM/VT reduces the number of infected hosts by 20% compared to d-ACTM.

Journal

Details 詳細情報について

Report a problem

Back to top