TY - GEN
T1 - ACTM
T2 - 20th International Conference on Advanced Information Networking and Applications
AU - Kawaguchi, Nobutaka
AU - Azuma, Yusuke
AU - Ueda, Shintaro
AU - Shigeno, Hiroshi
AU - Okada, Ken Ichi
PY - 2006/11/22
Y1 - 2006/11/22
N2 - In this paper we propose a novel worm detection method that can detect silent worms in intranet. Most existing detection methods use aggressive activities of worms as a clue for detection and are ineffective against worms that propagate silently using a list of vulnerable hosts. To detect such worms, we propose Anomaly Connection Tree Method (ACTM). ACTM uses two features present to most worms. First is that the worms's propagation behaviour is expressed as tree-like structures. Second is that the worm's selection of infection targets does not consider which hosts its infected host communicates to frequently. Then, by constructing trees that are composed of anomaly connections, ACTM detects the existence of such worms. Through the simulation results, we have shown that ACTM can detect the worms in an early stage.
AB - In this paper we propose a novel worm detection method that can detect silent worms in intranet. Most existing detection methods use aggressive activities of worms as a clue for detection and are ineffective against worms that propagate silently using a list of vulnerable hosts. To detect such worms, we propose Anomaly Connection Tree Method (ACTM). ACTM uses two features present to most worms. First is that the worms's propagation behaviour is expressed as tree-like structures. Second is that the worm's selection of infection targets does not consider which hosts its infected host communicates to frequently. Then, by constructing trees that are composed of anomaly connections, ACTM detects the existence of such worms. Through the simulation results, we have shown that ACTM can detect the worms in an early stage.
UR - http://www.scopus.com/inward/record.url?scp=33751082699&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33751082699&partnerID=8YFLogxK
U2 - 10.1109/AINA.2006.70
DO - 10.1109/AINA.2006.70
M3 - Conference contribution
AN - SCOPUS:33751082699
SN - 0769524664
SN - 9780769524665
T3 - Proceedings - International Conference on Advanced Information Networking and Applications, AINA
SP - 901
EP - 906
BT - Proceedings - 20th International Conference on Advanced Information Networking and Applications
Y2 - 18 April 2006 through 20 April 2006
ER -