Detection Algorithm of Internet Worm Eruption and Its Application

WEN Shi-qiang,DUAN Hai-xin,WU Jian-ping
DOI: https://doi.org/10.3969/j.issn.1000-7024.2005.05.007
2005-01-01
Abstract:New internet worm including many attack measures, such as virus, trojan and DDDS, will cause network block even paralysis, when it breaks out. A detection algorithm is brought forward which can find abnormity in the forepart of worm eruption by detection on variable rate of network flux, and then network administrators and emergency response teams can gain more time to take measures before worm blocks the network. This algorithm is evaluatedby DARPA98 intrusion detection evaluation system and has applied to real flux data of worm (Blaster、Nachi、slammer) eruption.
What problem does this paper attempt to address?