Download:
by Cliff C. Zou, Don Towsley, Weibo Gong, Songlin Cai
http://tennis.ecs.umass.edu/~czou/research/routingWorm-PADS05.pdf
Add To MetaCart
Abstract:
Most well-known worms, such as Code Red, Slammer, Blaster, and Sasser, infected vulnerable computers by scanning the entire IPv4 address space. In this paper, we present an advanced worm called “routing worm”, which implements two advanced attacking techniques. First, a routing worm uses BGP routing tables to only scan the Internet routable address space, which allows it propagate three times faster than a traditional worm. Second, and more importantly, the geographic information of BGP routing prefixes enables a routing worm to conduct pinpoint “selective attacks ” by imposing heavy damage to vulnerable computers in a specific country, company, Internet Service Provider, or Autonomous System, without collateral damage done to others. Because of the inherent publicity of BGP routing tables, attackers can easily deploy routing worms, which distinguishes the routing worm from other “worst-case ” worms. Compared to a traditional worm, a routing worm could possibly cause more severe congestion to the Internet backbone since all scans sent out by a routing worm are Internet routable (and can only be dropped at the destinations). In addition, it is harder to quickly detect a routingworm infected computer since we cannot distinguish illegal scans from regular connections without waiting for traffic responses. In order to defend against routing worms and all scanning worms, an effective way is to upgrade the current Internet from IPv4 to IPv6, although such an upgrade will require a tremendous effort and is still a controversial issue. 1.
Citations
|
314
|
How to Own the Internet in Your Spare Time
– Staniford, Paxson, et al.
- 2002
|
|
144
|
Code-Red: a case study on the spread and victims of an Internet worm
– Moore, Shannon, et al.
- 2002
|
|
121
|
Code red worm propagation modeling and analysis
– Zou, Gong, et al.
- 2002
|
|
113
|
L.: An investigation of geographic mapping techniques for Internet hosts
– Padmanabhan, Subramanian
- 2001
|
|
94
|
Monitoring and early warning for internet worms
– Zou, Gao, et al.
- 2003
|
|
93
|
Modeling the spread of active worms
– Chen, Gao, et al.
- 2003
|
|
79
|
Very fast containment of scanning worms
– Weaver, Staniford, et al.
- 2004
|
|
78
|
Directed-graph Epidemiological Models of Computer Viruses
– Kephart, White
- 1991
|
|
78
|
A taxonomy of computer worms
– Weaver, Paxson, et al.
- 2003
|
|
47
|
Containment of scanning worms in enterprise networks
– Staniford
|
|
46
|
A Tour of the Worm
– Seeley
- 1989
|
|
44
|
Measuring and modeling computer virus prevalence
– KEPHART, R
- 1993
|
|
41
|
Fast detection of scanning worm infections
– Jung, Schechter, et al.
- 2004
|
|
41
|
An Effective Architecture and Algorithm for Detecting Worms with Various Scan Techniques
– Wu, Vanagala, et al.
- 2004
|
|
38
|
Epidemic Modelling: An Introduction
– Daley, Gani
- 1999
|
|
31
|
Internet Protocol Version 6 (IPv6) Addressing Architecture", RFC 3513
– Hinden, Deering
- 2003
|
|
29
|
Computers and epidemiology
– Kephart, Chess, et al.
- 1993
|
|
24
|
Warhol Worm: The Potential for Very Fast Internet Plagues
– Weaver
|
|
19
|
The spread of the witty worm. http:// www.caida.org/analysis/security/witty
– Moore, Shannon
|
|
18
|
Where in the world is netgeo.caida.org
– Periakaruppan, Donohoe
- 2000
|
|
18
|
On the Performance of Internet Worm Scanning Strategies
– Zou, Towsley, et al.
- 2003
|
|
15
|
to 0wn the Internet in Your Spare Time
– How
|
|
11
|
Coupled KermackMcKendrick model for randomly scanning worms
– Kesidis, Hamadeh, et al.
- 2005
|
|
10
|
Dynamic Graphs of the Nimda worm. http://www.caida.org/dynamic/analysis/security/nimda
– CAIDA
|
|
8
|
RFC 2373: IP version 6 addressing architecture
– Hinden, Deering
- 1998
|
|
7
|
RFC 3041: Privacy Extensions for Stateless Address Autoconfiguration
– Narten, Draves
- 2001
|
|
5
|
Finding a host’s geographical location
– Raz
|
|
4
|
Today News. The cost of Code Red: $1.2 billion
– USA
|
|
4
|
RFC-3587: IPv6 global unicast address format
– Hinden, Deering, et al.
- 2003
|
|
3
|
BGP-system usage of 32 bit Internet address space
– Braun
- 1997
|
|
3
|
Visualizing Internet Topology at a Macroscopic Scale. http://www.caida.org/analysis/topology/as core network
– CAIDA
- 2003
|
|
3
|
Computer worm grounds flights, blocks ATMs
– News
|
|
2
|
The Evolving Virus Threat
– Nachenberg
- 2000
|
|
2
|
v4 Address Space Utilization
– IP
- 1998
|
|
2
|
Map project
– World
- 1979
|
|
2
|
IPv4 BGP geopolitical analysis
– CAIDA
- 2003
|
|
2
|
Models of internet worm defense. IMA Workshop 4: Measurement, Modeling and Analysis of the Internet
– Nicol
- 2004
|
|
1
|
Hemminger et al. IPv6: An Internet Evolution. http://www.ipv6forum.org/navbar/papers/IPv6-an-Internet-Evolution.pdf
– Chown, Doyle, et al.
|
|
1
|
Border Gateway Protocol (BGP). http://www.cisco.com/univercd/cc/td/doc/cisintwk/ito doc/bgp.htm
– Documents
|
|
1
|
Routing information service R.I.S. design note. http://www.ripe.net/projects/ris/Notes/ripe-200
– Antony, Uijterwaal
- 1999
|
|
1
|
IPv4 address space utilization
– CAIDA
- 1998
|
|
1
|
Reserved IPv4 addresses. http://www.cidr-report.org/v6/reserved-ipv4.html
– IANA
- 2004
|
|
1
|
world map project: IP address locator tool. http://www.geobytes.com/IpLocator.htm?GetLocation
– Net
|
|
1
|
Security implications of IPv6
– Warfield
- 2003
|