Real-Time Virus Detection System Using iNetmon Engine

Sureswaran Ramadass, Azlan Bin Osman, Rahmat Budiarto · 2003

The fundamental problem with any network administration systems today is its ability to cope with the rising amount of virus intrusions. Currently available systems are only able to detect a virus after the network has been infected, therefore its non-real time. Depending on the malicious activities of the viruses, the detection will be carried out. Herewith, we are proposing a Real-Time Virus Detection system, which detects the arrival of virus intruders at the network layer rather than at the application layer. In this paper, we present an overview of the system design, which uses the iNetmon engine, Virus parser, Virus Matching Engine and alert mechanisms. Using the iNetmon engine, all packets traversing through the network nodes are captured; these packets are decoded and sent to Virus Matching Engine. Meanwhile, Virus parser will load the entire virus signature to memory. At the Virus Matching Engine, captured packet will be formatted to enhance matching speed. Then the formatted packet content will be scanned for virus information. Once the packet is known to contain virus or worm information, alert mechanism will alert the network administrator. Upon receiving this alert message, the administrator can now take necessary actions before the packet arrives at the destination.

Read the paper · More papers on PaperTik