See this document in CiteSeerX!

The Limits of Global Scanning Worm Detectors  (Make Corrections)  
in the Presence of Background Noise David W. Richardson, Steven D. Gribble,...



  Home/Search   Context   Related

 
View or download:
columbia.edu/~ange...m30richardson.pdf
Cached:  PDF   PS.gz  PS  Image  Update  Help

From:  columbia.edu/~angelos...wormprog (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Internet worms cause billions of dollars in damage each year. To combat them, researchers have been exploring global worm detection systems to spot a new random scanning worm outbreak quickly. These systems passively listen for worm probes on unused IP addresses, looking for anomalous increases in probe tra#c to distinguish the emergence of a new worm from background Internet noise. (Update)

Active bibliography (related documents):   More   All
0.7:   Fast Detection of Scanning Worm Infections - Jaeyeon Jung Stuart (2004)   (Correct)
0.6:   A Firewall Network System for Worm Defense in Enterprise.. - Zou, Towsley, Gong   (Correct)
0.6:   Feedback Email Worm Defense System For Enterprise Networks - Zou, Gong, Towsley (2004)   (Correct)

Similar documents based on text:
0.0:   Unknown -   (Correct)

BibTeX entry:   (Update)

@misc{ presence-limits,
  author = "In The Presence",
  title = "The Limits of Global Scanning Worm Detectors",
  url = "citeseer.ist.psu.edu/743733.html" }
Citations (may not include all citations):
74   Code-red: a case study on the spread and victims of an Inter.. - Moore, Shannon et al. - 2002
69   How to 0wn the Internet in your spare time - Staniford, Paxson et al. - 2002
53   Code red worm propagation modeling and analysis - Zou, Gong et al. - 2002
36   IEEE Security and Privacy (context) - Moore, Paxson et al. - 2003
33   Modeling the spread of active worms - Chen, Gao et al. - 2003
30   Monitoring and early warning for Internet worms - Zou, Gao et al. - 2003
29   distributed worm signature detection (context) - Kim, Karp et al. - 2004
23   Automated worm fingerprinting - Singh, Estan et al. - 2004
23   Fast portscan detection using sequential hypothesis testing - Jung, Paxson et al. - 2004
22   Very fast containment of scanning worms (context) - Weaver, Staniford et al. - 2004
11   Characteristics of Internet background radiation - Pang, Yegneswaran et al. - 2004
10   Designing a framework for active worm detection on global ne.. (context) - Berk, Bakos et al. - 2003
10   Worm propagation modeling and analysis under dynamic quarant.. - Zou, Towsley et al. - 2003
9   Recent worms: A survey and trends (context) - Kienzle, Elder - 2003
8   Using sensor networks and data fusion for early detection of.. (context) - Berk, Gray et al. - 2003
8   Honeystat: Local worm detection using honeypots (context) - Dagon, Qin et al. - 2004
7   selective attack worm based on IP address information (context) - Zou, Towsley et al. - 2003
4   Dns-based detection of scanning worms in an enterprise netwo.. - Whyte, Kranakis et al. - 2005
4   Early detection of Internet worm activity by metering ICMP d.. (context) - Bakos, Berk - 2002
3   Toward understanding distributed blackhole placement (context) - Cooke, Bailey et al. - 2004
3   ACM SIGCOMM Computer Communication Review (context) - Spa, Internet et al. - 1989
2   early warning and response based on local victim information (context) - Gu, Sharif et al. - 2004
2   Epidemic Modeling: An Introduction (context) - Daley, Gani
2   Worm detection using local networks - Qin, Dagon et al. - 2004
1   Simulating realistic network worm tra#c for worm warning sys.. (context) - Liljenstam, Nicol et al. - 2003
1   ective architecture and algorithm for detecting worms with v.. (context) - Wu, Vangala et al. - 2004
1   Fusion and filtering in distributed intrusion detection syst.. - Barford, Jha et al. - 2004
1   Fast detecton of scanning worm infections (context) - Schechter, Jung et al. - 2004

Documents on the same site (http://www1.cs.columbia.edu/~angelos/worm05/worm-prog.html):   More
Defending against Hitlist Worms using Network Address - Space Randomization Antonatos   (Correct)
On the Effectiveness of Automatic Patching - Vojnovic, Ganesh   (Correct)
A Self-Learning Worm Using Importance Scanning - Zesheng Chen Georgia   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC