Leveraging anonymised network traces for the assessment of the potential virulence of contemporary network worm outbreaks
Luc Tidy, Steve Woodhead · 2015
Network worms present a persistent threat to cyber-security, with novel wormable vulnerabilities being discovered regularly. In order to assess the potential impact of a network worm outbreak that has yet to occur, both the vulnerability that is going to be exploited, as well as the number of susceptible hosts needs to be identified. Although detailed information is being catalogued and classified, issues persist in determining a representative metric for the number of susceptible hosts for a given vulnerability. This paper presents a novel analytical method of leveraging network traces for the assessment of potential network worm outbreaks, with case studies provided for three recent wormable vulnerabilities (circa. 2012-2014). The resulting metrics are then used as inputs to the Internet Worm Simulator to demonstrate the cyber-epidemiological assessment that can be provided using this method.