会议论文详细信息
6th Symposium on Operating Systems Design & Implementation
Automated Worm Fingerprinting
Sumeet Singh ; Cristian Estan ; George Varghese ; Stefan Savage
PID  :  75316
来源: CEUR
PDF
【 摘 要 】

Network worms are a clear and growing threat to the se curity of today’s Internetconnected hosts and networks. The combination of the Internet’s unrestricted connec tivity and widespread software homogeneity allows net work pathogens to exploit tremendous parallelism in their propagation. In fact, modern worms can spread so quickly, and so widely, that no humanmediated reaction can hope to contain an outbreak. In this paper, we propose an automated approach for quickly detecting previously unknown worms and viruses based on two key behavioral characteristicsa common exploit sequence together with a range of unique sources generating infections and destinations be ing targeted. More importantly, our approachcalled “content sifting”automatically generates precise sig natures that can then be used to filter or moderate the spread of the worm elsewhere in the network. Using a combination of existing and novel algorithms we have developed a scalable content sifting implemen tation with low memory and CPU requirements. Over months of active use at UCSD, our Earlybird prototype system has automatically detected and generated signa tures for all pathogens known to be active on our network as well as for several newworms and viruses which were unknown at the time our system identified them. Our initial experience suggests that, for a wide range of net work pathogens, it may be practical to construct fully automated defenseseven against socalled “zeroday”

【 预 览 】
附件列表
Files Size Format View
Automated Worm Fingerprinting 1240KB PDF download
  文献评价指标  
  下载次数:7次 浏览次数:3次