Hitlist Worm Detection using Source IP Address History.

Jeffrey Chan, Christopher A. Leckie, Tao Peng · 2006

Abstract — Internet worms are a growing menace due to their increasing sophistication and speed of propagation. In this paper, we present a new worm detection scheme, History-based IP Worm Detection. It uses the difference in the distribution of source addresses between regular users and scanning hosts to distinguish between worm probes and normal accesses. This property is used to implement a weighted source address counting scheme, and a change point detection technique is used to detect surges in the rate of source addresses seen. In contrast to many existing techniques for worm detection, our approach is able to detect worms that only scan active addresses, while having linear time complexity. I.

Read the paper · More papers on PaperTik