Approach to Early Detection and Defense Against Internet Worms

CHEN Bo,FANG Bin-xing,YUN Xiao-chun
DOI: https://doi.org/10.3321/j.issn:1000-436x.2007.02.002
2007-01-01
Abstract:A distributed defense mechanism was proposed.The main task of defense mechanism was to quickly detect worm attacks and response to constrain their propagation.The defense mechanism was composed of two parts: a date processing centre(DPC) and distributed sensors for defending against worm attacks.DPC is responsible for receiving the result of each distributed sensor and computing the number of infected computer.These distributed sensors monitor the network and detect worm.Once a worm attack was detected,a dropping packet mechanism is used so that the worm propagation was con-strained,and the number of interference with normal activity is minimized.The experimental results prove the robustness and efficiency of the proposed defense mechanism.
What problem does this paper attempt to address?