Using NetFlow analysis to detect worm propagation

Kjell Tore Fossbakk · NORA - Norwegian Open Research Archives · 2010

ENGELSK: The Internet has become the main network for commerce, recreation and communication and this has increased the need to protect sensitive information. Computer worms will continue to pose a major threat to us, as they can readily propagate vulnerable computers on the Internet. Worms and other malware can spread quickly and do extensive damage, with some having the ability to mutate themselves (polymorphic worms) and their propagation pattern for each infection. Network Intrusion Detection Systems (NIDSs) is one method to detect such worms. The traditional NIDSs detect misuse by matching network information with pre-defined rules, this is called signature-based detection. A polymorphic worm can adversely impact the accuracy of a NIDS based on signatures, when it mutates itself. This motivates us to examine alternative methods of network intrusion detection. NetFlow analysis is a method that uses meta-data information about network traffic connections between hosts. All information from packets between two hosts is stored in what we call a NetFlow record. In this thesis, we investigate if it feasible to detect worm propagation using NetFlow analysis. By using recursion on the NetFlow records and visualization of the results in a histogram; we assess if there is an indication of worm propagation in the network traffic. In addition, we compare this method with a traditional signature-based detection system, Snort, when monitoring a polymorphic worm and assess if NetFlow analysis is more robust than Snort.

Read the paper · More papers on PaperTik