2008
DOI: 10.2197/ipsjdc.4.79
|View full text |Cite
|
Sign up to set email alerts
|

d-ACTM/VT: A Distributed Virtual AC Tree Detection Method

Abstract: In this paper, we propose d-ACTM/VT, a network-based worm detection method that effectively detects hit-list worms using distributed virtual AC tree detection. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. To addres… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Year Published

2011
2011
2011
2011

Publication Types

Select...
1

Relationship

1
0

Authors

Journals

citations
Cited by 1 publication
(2 citation statements)
references
References 13 publications
0
2
0
Order By: Relevance
“…In the evaluation, we assess the effect of T w on the detection performance. T H AC is adjusted to 30 to achieve the given false alert interval using the threshold-adjusting algorithm 2) .…”
Section: Ids Settingsmentioning
confidence: 99%
See 1 more Smart Citation
“…In the evaluation, we assess the effect of T w on the detection performance. T H AC is adjusted to 30 to achieve the given false alert interval using the threshold-adjusting algorithm 2) .…”
Section: Ids Settingsmentioning
confidence: 99%
“…Kawaguchi, et al proposed a method called d-ACTM/VT 2) , for detecting hit-list worms that attack internal hosts in an enterprise network by finding their propagation trees in a distributed manner. A propagation tree represents a worm's propagation routes in a network.…”
Section: Introductionmentioning
confidence: 99%