AM ONITORING SYSTEM FOR MITIGATING FAST PROPAGATING WORMS IN THE NETWORK INFRASTRUCTURE
Miguel Vargas Martín · 2005
Typically, intrusion detection systems deal with detection and response to a computer worm itself, but not with the collateral damage caused by the worm’s propagation. We present a monitoring system that classifies outbound packets within a router. This classification scheme results in a dynamic bandwidth share for packets where those that repeat disruptively are put into busy queues, whereas the rest are put into emptier queues. One of the major advantages of this approach is that the diagnosis of worm activity is less relevant since any disruptive traffic (worm or otherwise) will get limited bandwidth, consequently throttling some polymorphic worms, encrypted worms, denial-of-service (DoS) and distributed DoS attacks, abusive use of network services, and congestion due to flash crowds. There are some limitations to this system, all of which are acceptable in many applications.