Contain Internet Worm with Domain Name Service in Large Scale Network

Zheng Hui,Sun Bin,Zheng Xianwei,Duan Haixin
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.08.033
2006-01-01
Abstract:In large scale network,a mass of susceptible machines and infected machines form a prefect environment for Internet worm living.Setting ACL on router only works at the beginning of worm broken out to steady situation,but there are still lots of infected machines in network after that.It would be a long term if network operators passively wait for each user to eliminate worm from his infected machine by himself.In this paper,it is discussed that taking advantage of DNS hijacking lead user's traffic to a warning machine so that user can be informed there are some thing wrong with his machine and know how to deal with the problems.The concrete DNS-hijacking-containing project was implemented in Tsinghua University and the statistics of data shows that Internet worms are cleared up very quickly in a large scale network as Tsinghua University.
What problem does this paper attempt to address?