Research on Worm Epidemics and Visualization in High-Speed Links

LIU Peng,XIAO Zong-shui,LI Wei
DOI: https://doi.org/10.3969/j.issn.1000-7024.2006.09.032
2006-01-01
Abstract:Worm epidemic might spread at unprecedented high speed in high-speed links.And it is very necessary to design a compre-hensive automated defense system.The design of the system must base on high reliable detection accuracy and real-time traffic analysis.To solve these problems,a detecting method was presented which is based on the visualization of worm traffic flow.A simple and novel visualization scheme was introduced,which plots a packet in a 3-dimensional space using its source IP address,destination IP address and the destination port.After the high-speed link's traffic flow is visualized through this scheme,worms could be detected easily.Based on this character,an efficient attack detection and classification algorithm was brought forth.
What problem does this paper attempt to address?