Design and Implementation of Bro-based Worm Detection System

Xiang Zhengtao,Chen Li,Dong Yabo
DOI: https://doi.org/10.3969/j.issn.1008-5483.2008.01.007
2008-01-01
Abstract:Based on the analysis of worm propagating mechanism and the framework of Bro—an intrusion detection system,the Bro-based worm detection system is designed and implemented.The failure frequency of FCC(First Contact Connections) and heavy-tailed property based worm detection algorithm is used as the kernel of the detection system.The detecting system extends the policy script interpreter of Bro,which sends the detecting results to the share memory based on the implementation of the policy script of the detecting algorithm.The results in the share memory are then sent to the monitor based on the SNMP,which is convenient for real-time monitoring the network worms.The worm detection system can detect network worm hosts quickly and accurately.
What problem does this paper attempt to address?