Internet-Worm Detecting System Based on ISP Distributed

ZHAO Ye-hong,YANG Shou-bao,WANG Shao-lin,DONG Kuo
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.34.030
2006-01-01
Abstract:The traditional approach keeping track of TCP SYN packets needs massive probe's memory and computation resources.An Internet-worm early detecting system based on ISP distributed is proposed in this paper,which relies on TCP RESET packet detecting to find the scan sources.Compared to existing methods,our approach has the merits of detecting the suspicious Internet worms,defending the forge attack,and reducing 59.4% and 28.9% overhead in normal and in simulation worm scanning respectively.
What problem does this paper attempt to address?