Analysis of Abnormalities of Worm Traffic for Obtaining Worm Detection Vectors

Zhengtao Xiang,Yufeng Chen,Yabo Dong,Honglan Lao
DOI: https://doi.org/10.1007/11760146_61
2006-01-01
Abstract:Scanning traffic is the majority of worm traffic. Gaining deep insight into worm traffic can do much help in detecting worm hosts. The distributions of vectors related with First Contact Connections (FCC) of legitimate hosts and worm hosts are analyzed. The vectors are arrival interval, request size, response size, duration and RTT. Distributions of these vectors of worm traffic show abnormalities of the lack of heavy-tailed character, which is hold by that of legitimate traffic. Besides high probability of failed FCC, arrival interval and request size can be used as additional vectors.
What problem does this paper attempt to address?