Abstract:
activities to model and analyze Internet worm propagation. In this paper we provide a careful analysis of Code Red propagation by accounting for two factors: one is the dynamic countermeasures taken by ISPs and users; the other is the slowed down worm infection rate because Code Red rampant propagation caused congestion and troubles to some routers. Based on the classical epidemic Kermack-Mckendrick model, we derive a general Internet worm model called the twofactor worm model. Simulations and numerical solutions of the two-factor worm model match the observed data of Code Red worm better than previous models do. This model leads to a better understanding and prediction of the scale and speed of Internet worm spreading.
Citations
|
122
|
The Mathematical Theory of Infectious Diseases and its Applications
– BAILEY
- 1975
|
|
78
|
Directed-graph Epidemiological Models of Computer Viruses
– Kephart, White
- 1991
|
|
59
|
Observation and analysis of BGP behavior under stress
– Wang, Zhao, et al.
- 2002
|
|
51
|
Infectious diseases of humans: Dynamics and control
– ANDERSON, MAY
- 2002
|
|
44
|
Measuring and modeling computer virus prevalence
– KEPHART, R
- 1993
|
|
38
|
How to 0wn the Internet
– Staniford, Paxson, et al.
- 2002
|
|
29
|
Computers and epidemiology
– Kephart, Chess, et al.
- 1993
|
|
24
|
Warhol Worm: The Potential for Very Fast Internet Plagues
– Weaver
|
|
18
|
Global Routing Instabilities during Code Red II and Nimda Worm Propagation
– Cowie, Ogielski, et al.
- 2001
|
|
18
|
The internet worm incident
– Spafford
- 1991
|
|
15
|
Stochastic Epidemic Models and Their Statistical Analysis
– Andersson, Britton
- 1999
|
|
9
|
A fluid based analysis of a network of AQM routers supporting TCP flows with an application to RED
– Misra, Gong, et al.
- 2000
|
|
8
|
Mathematical modeling in epidemiology
– Frauenthal
- 1980
|
|
8
|
On Viral Propagation and the Effect of Immunization
– Wang, Knight, et al.
- 2000
|
|
2
|
The Spread of the Code-Red Worm
– Moore
|
|
2
|
The Evolving Virus Threat
– Nachenberg
- 2000
|
|
1
|
Security Advisory: “Code Red
– Cisco
|
|
1
|
notes: Dealing with mallocfail and High CPU Utilization Resulting From the “Code Red” Worm. http://www.cisco.com/warp/public/63/ ts codred worm.shtml
– Tech
- 1985
|
|
1
|
Visual simulation of Code Red worm propagation patterns
– Heberlein
|
|
1
|
Virulent worm calls into doubt our ability to protect the Net
– Lemos
|
|
1
|
Microsoft reveals Web server hole
– Lemos
|