Origins: an approach to trace fast spreading worms to their roots

  • Authors:
  • Andrew L. Burt;Michael Darschewski;Indrajit Ray;Ramakrishna Thurimella;Hailin Wu

  • Affiliations:
  • Techsoft, P.O. Box 16143, Golden, CO 80402, USA.;University of Denver, Denver, CO 80210, USA.;Colorado State University, Fort Collins, CO 80523, USA.;University of Denver, Denver, CO 80210, USA.;Array Networks, Milpitas, CA 95035, USA

  • Venue:
  • International Journal of Security and Networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

An automatic distributed mechanism is proposed to identify thepropagation roots of fast spreading internet worms. The informationobtained can be used to identify local worm outbreaks, identifynetwork intrusion, identify internal network misuse, and help withthe forensic trace-back after detection. It has been designed withsimplicity, efficacy, and ease of deployment in mind. Two modes ofoperation are possible, yielding both real-time and post mortempropagation information. The proposed paradigm can work in unisonwith any intrusion detection, throttling and human-mediatedresponses. Simulation results show that even with only 20 30%deployment, worm origins can be pinpointed with greatprecision.