Catching instant messaging worms with change-point detection techniques

  • Authors:
  • Guanhua Yan;Zhen Xiao;Stephan Eidenbenz

  • Affiliations:
  • Information Sciences, Los Alamos National Laboratory, Los Alamos, NM;School of Electronics Engineering & Computer Science, Peking University, Beijing, P. R. China;Information Sciences, Los Alamos National Laboratory, Los Alamos, NM

  • Venue:
  • LEET'08 Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats
  • Year:
  • 2008

Quantified Score

Hi-index 0.01

Visualization

Abstract

Instant messaging (IM) systems have gained a lot of popularity in recent years. The increasing number of IM users has lured malware authors to develop more worms and viruses that spread in IM networks. In response to such growing security threat to IM systems, it is imperative to develop a fast and responsive IM worm detection system. In this paper, we apply change-point detection techniques to catch two families of IM worms, one aimed at infecting all vulnerable machines as quickly as possible and the other aimed at spreading slowly in a stealthy fashion to evade detection. Experimental results demonstrate that the proposed solutions are very effective in detecting both families of IM worms.