International Conference on Dependable Systems and Networks (DSN'06)
DOI: 10.1109/dsn.2006.6
|View full text |Cite
|
Sign up to set email alerts
|

A Multi-Resolution Approach forWorm Detection and Containment

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
25
0

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 36 publications
(25 citation statements)
references
References 15 publications
0
25
0
Order By: Relevance
“…The MRW detector was first published in 2006 [6]. It is based on the observation that whereas worm scanning results in connections to many destinations, during legitimate operations the growth curve of the number of distinct destinations over time is concave.…”
Section: The Selected Worm Detectorsmentioning
confidence: 99%
See 2 more Smart Citations
“…The MRW detector was first published in 2006 [6]. It is based on the observation that whereas worm scanning results in connections to many destinations, during legitimate operations the growth curve of the number of distinct destinations over time is concave.…”
Section: The Selected Worm Detectorsmentioning
confidence: 99%
“…After our exhaustive evaluation of worm detectors, we are left with the following selections: TRW [7], RBS [20], TRWRBS [20], PGD [21], DSC [8], and MRW [6]. We discuss these detectors in greater detail in the next section.…”
Section: Detector Selectionmentioning
confidence: 99%
See 1 more Smart Citation
“…Most existing containment schemes impose a single threshold rate on the entire host, such as several distinct IP connections per second, regardless of the application demands, thus affecting the performance of legitimate applications. Sekar et al [11] proposed use of different detection thresholds during different time windows, but they still applied these thresholds without differentiating processes on the host.…”
Section: Introductionmentioning
confidence: 99%
“…However, it was acknowledged that if the worm speed is slow enough to cause interspersed traffic throughout a large amount of normal traffic, detection with the SWORD system becomes difficult. In [3] a multi-resolution approach for worm detection was proposed to deal with the limitations of simple threshold-based detection methods. Using a number of unique destinations contacted as a basis for anomaly detection, the multi-resolution approach used different thresholds during different time windows to detect attacks of different speeds.…”
Section: Introduction and Related Workmentioning
confidence: 99%