Is early warning of an imminent worm epidemic possible?

  • Authors:
  • Hyundo Park;Hyogon Kim;Heejo Lee

  • Affiliations:
  • Korea University;Korea University;Korea University

  • Venue:
  • IEEE Network: The Magazine of Global Internetworking
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

This article introduces a novel anomaly detection method that makes use of only matrix operations and is highly sensitive to randomness in traffic. The sensitivity can be leveraged to detect attacks that exude randomness in traffic characteristics, such as denial-of-service attacks and worms. In particular, we show that the method can be used to alert of the imminent onset of a worm epidemic in a statistically sound manner, irrespective of the worm's scanning strategies.