Early Warning of Active Worms Based on Multi-Similarity

H He,HL Zhang,WZ Zhang,MZ Hu,ZJ Tang
DOI: https://doi.org/10.1109/icmlc.2005.1527616
2005-01-01
Abstract:Worm detection methods play an important role as frequent breakouts of Internet worm result in tremendous economic destruction. On the basis of analyzing characteristics of normal network traffic distribution, an early worm detection method based on multi-similarity is proposed. It integrates the worms' behavior attribute with its traffic distribution and detects abnormal behavior by its distribution similarity of its certain features. According to the network simulation experiments, the detection method can find out the worms intrusion against the large-scale network traffic, which does not arouse the sharp changes of the network traffic.
What problem does this paper attempt to address?