Worm detection and auto-signature extraction in large scale network
Yi Xin, Fangbingxing Yunxiaochun · 2005
Nowadays, worms have been one of the leading threats to information security and service availability. Current operational practices have not been able to manage the threat effectively. So it is very important to make early warning of the burst of worm in large scale network and extract the network signature automatically. Based on the TCP/IP Flows, the paper introduces a novel methodology to analyze the feature attributes of network traffic flow, including real-time data detection and traffic models. Integrated with data preprocessing, we construct an auto-signature extraction algorithm. We deployed them in our campus network (more than 20000 compuers with 400M/s). It is shown that the worms are detected with more efficiency and the worm signature is extracted accurately.