CBSTM: Cloud-based Behavior Similarity Transmission Method to Detect Industrial Worms

  • Authors:
  • Huayang Cao;Peidong Zhu;Jinjing Zhao

  • Affiliations:
  • Computer School National University of Defense Technology Changsha, China;Computer School National University of Defense Technology Changsha, China;National Key Laboratory of Science and Technology on Information System Security Beijing, China

  • Venue:
  • Proceedings of the Second International Conference on Innovative Computing and Cloud Computing
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Sophisticated industrial worms, such as Stuxnet, Flame, Duqu, have brought much threat in industrial networks. Most existing detection methods use content pattern or aggressive activities as a clue to the existence of worms, which are ineffective against worms that don't have their pattern been known and don't behave aggressively. To detect such worms, we proposed Cloud-based Behavior Similarity Transmission Method (CBSTM). CBSTM is a cloud-based method that utilizes the fundamental feature that a worm propagates from host to host. It monitors behaviors on each host in industrial networks. When same behaviors propagate among hosts and meet given criteria, corresponding hosts are believed to be infected by worms. When the worm is detected, the found behavior sequence is used as this worm's signature to realize instant worm detection afterwards. Since CBSTM doesn't need specific characteristics of worms, it can be generally applied to detecting any worms in industrial networks. The evaluation with detecting Stuxnet confirms the effectiveness of CBSTM.