Worm Attack Detection and Response
Chen Bo,Yu Xiangzhan,Fang Binxing,Yun Xiaochun
DOI: https://doi.org/10.1007/s11460-007-0087-7
2007-01-01
Frontiers of Electrical and Electronic Engineering in China
Abstract:There appear many Internet-scale worm incidents in recent years, which have caused severe damage to the society. It is clear that a simple self-propagation worm can quickly spread across the Internet. Therefore, it is necessary to implement automatic mitigation which can detect worm and drop its packet. In this paper, the worm’s framework was first analyzed and its two characteristics were detected. Based on the two characteristics, a defending algorithm was presented to protect network. Experimental results verify that our algorithm is very effective to constrain the worm propagation and meanwhile it almost does not interfere in normal activity.