A User Habit Based Approach to Detect and Quarantine Worms.

Ping Wang,Fang Bin-Xing,Xiao-chun Yun
DOI: https://doi.org/10.1109/ICC.2006.255088
2006-01-01
Abstract:In the long term usage of the network, users will form certain types of habit according to their specific characteristics, individual hobbies and given restrictions. On the burst-out of worms, the overwhelming flow caused by worm's scanning will temporarily alter the behavior representation of users. Therefore, it is reasonable to conclude that the statistics and classification of user habits can contribute to the detection of worms. We observe that number of destinations accessed in a long time range by a user is approximately limited, it means possible to record the access habit of users. Based on the analysis of both users and worms, we construct the patterns of user-habit and propose a new approach for the early warning of worms. And a better quarantine strategy is proposed to insure the normal access of user. © 2006 IEEE.
What problem does this paper attempt to address?