Network Traffic Flow Analysis And Its Application In Early Detection Of Internet Worms

ZM Cai,TH Qin,X Guan,XB Ma,XM Zhou
2006-01-01
Abstract:Internet is perhaps the most complex man-made system. Its complexity makes internet security a very hard problem which attracts a lot of research interests. Recent large-scale and fast spreading internet worms led to researches in automated containment against self-propagating worms and early worm detection is widely believed as the essential choke point of worm containment. In this paper, two new concepts, flow intensity and flow distribution intensity, are proposed to capture fundamental characteristics of network traffic. Although raw network traffics are non-stable, we find that the calculated flow intensity and flow distribution intensity are stable processes with non-zero means. We also find that the abnormal network behavior, e.g. occurrences of worms, will lead to significant changes of the stable process's mean and variance. EWMA (Exponential Weighted Moving Average) control charts are applied to the detection of the change point and in turn the detection of early worm propagation. The extensive experimental results show that our method detects early worm propagation in local networks both quickly and accurately.
What problem does this paper attempt to address?