Worm Intrusion Alarm Modeling Based on Network Traffic Character

Lu Guang,Yu Fei,Guangxue Yue,Miaoliang Zhu
DOI: https://doi.org/10.1109/imsccs.2006.287
2006-01-01
Abstract:The research community is interested in finding effective methods to detect network traffic anomalies such as the propagation of a new worm, and to raise alarm in time. In this paper we research the principle that the number of network traffic can affect self-similarity of network traffics, and analyze the variety of self-similarity caused by abnormal network traffic. We propose a network traffic model on normal behaviors of users. An approach, which is applied to determine whether or not abnormal network traffic exists by comparing Hurst parameter with predefined threshold, is also presented. At last, implementation of network worm detecting agent in NP is described. Results of evaluation show that detecting agent performs very well in test-bed.
What problem does this paper attempt to address?