Defending against Hitlist Worms using Network Address Space Randomization

Jiang Bao-cheng · Microcomputer Information · 2009

It’s hard to detecting hitlist worm when it collects vulnerability in advance. And hitlist worm has a high speed of propagation , so automated defenses may not be able to react in a timly. The article examines a new proactive defense mechanism called network address space randomization whose objective is to harden networks specifically against hitlist worm. We explore and introduce a prototype of it as well as examining the effectiveness and limitations of the approach. The idea behind this method is that hitlist information could be rendered stale if hosts are forced to frequently change their IP addresses. Network address space randomization limits or slows down hitlist worms and forced them exhibit features that make them easier to clear at the perimeter.

Read the paper · More papers on PaperTik