Publication | Closed Access
Modeling the spread of active worms
499
Citations
6
References
2003
Year
Unknown Venue
Active Worms SpreadInfectious Disease ModellingInternet Traffic AnalysisNetwork ScienceEngineeringIntrusion Detection SystemInformation SecurityQuantitative AnalysisNetwork AnalysisComputer ScienceBotnet DetectionActive WormsNetwork Traffic MeasurementNetwork MonitoringParasitology
Active worms can rapidly flood the Internet, and modeling their spread helps understand propagation and devise monitoring and defense strategies, while no model yet exists for localized scanning worms, making this the first quantitative attempt. The study introduces the Analytical Active Worm Propagation (AAWP) model to characterize random scanning worm propagation and extends it to model local subnet scanning, marking the first quantitative effort in this area. The AAWP model is a mathematical framework for random scanning worm propagation, compared against the Epidemiological model and Weaver's simulator.
Active worms spread in an automated fashion and can flood the Internet in a very short time. Modeling the spread of active worms can help us understand how active worms spread, and how we can monitor and defend against the propagation of worms effectively. In this paper, we present a mathematical model, referred to as the Analytical Active Worm Propagation (AAWP) model, which characterizes the propagation of worms that employ random scanning. We compare our model with the Epidemiological model and Weaver's simulator. Our results show that our model can characterize the spread of worms effectively. Taking the Code Red v2 worm as an example, we give a quantitative analysis for monitoring, detecting and defending against worms. Furthermore, we extend our AAWP model to understand the spread of worms that employ local subnet scanning. To the best of our knowledge, there is no model for the spread of a worm that employs the localized scanning strategy and we believe that this is the first attempt on understanding local subnet scanning quantitatively.
| Year | Citations | |
|---|---|---|
Page 1
Page 1