Optimum Identification of Worm-Infected Hosts

  • Authors:
  • Noriaki Kamiyama;Tatsuya Mori;Ryoichi Kawahara;Shigeaki Harada

  • Affiliations:
  • NTT Service Integration Laboratories, Tokyo, Japan 180-8585;NTT Service Integration Laboratories, Tokyo, Japan 180-8585;NTT Service Integration Laboratories, Tokyo, Japan 180-8585;NTT Service Integration Laboratories, Tokyo, Japan 180-8585

  • Venue:
  • IPOM '08 Proceedings of the 8th IEEE international workshop on IP Operations and Management
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The authors have proposed a method of identifying superspreaders by flow sampling and a method of extracting worm-infected hosts from the identified superspreaders using a white list. However, the problem of how to optimally set parameters, 茂戮驴, the measurement period length, m*, the identification threshold of the flow count mwithin 茂戮驴, and H*, the identification probability for hosts with m= m*, remains unsolved. These three parameters seriously affect the worm-spreading property. In this paper, we propose a method of optimally designing these three parameters to satisfy the condition that the ratio of the number of active worm-infected hosts divided by the number of all the vulnerable hosts is bound by a given upper-limit during the time Trequired to develop a patch or an anti-worm vaccine.