Online Accumulation: Reconstruction of Worm Propagation Path

  • Authors:
  • Yang Xiang;Qiang Li;Dong Guo

  • Affiliations:
  • College of Computer Science and Technology, JiLin University, JiLin, China 130012;College of Computer Science and Technology, JiLin University, JiLin, China 130012;College of Computer Science and Technology, JiLin University, JiLin, China 130012

  • Venue:
  • NPC '08 Proceedings of the IFIP International Conference on Network and Parallel Computing
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Knowledge of the worm origin is necessary to forensic analysis, and knowledge of the initial causal flows supports diagnosis of how network defenses were breached. Fast and accurate online tracing network worm during its propagation, help to detect worm origin and the earliest infected nodes, and is essential for large-scale worm containment. This paper introduces the Accumulation Algorithm which can efficiently tracing worm origin and the initial propagation paths, and presents an improved online Accumulation Algorithm using sliding detection windows. We also analyzes and verifies their detection accuracy and containment efficacy through simulation experiments in large scale network. Results indicate that the online Accumulation Algorithm can accurately tracing worms and efficiently containing their propagation in an approximately real-time manner.