Self-propagating computer worms have been
terrorizing the Internet for the last several
years. With the increasing density,
inter-connectivity and bandwidth of the Internet
combined with security measures that inadequately
scale, worms will continue to plague the Internet
community. Existing anti-virus and intrusion
detection systems are clearly inadequate to defend
against many recent fast-spreading worms. In this
paper we explore an active counter-attack method -
anti-worms. We propose a method that transforms a
malicious worm into an anti-worm which disinfects
its original. The method is evaluated using the
CodeRed, Blaster and Slammer worms. We show through
simulation the effectiveness of an anti-worm with
several propagation schemes and its impact on the
overall network. We also discuss important
limitations of the proposed method.
Created and maintained by Mihai Christodorescu (http://www.cs.wisc.edu/~mihai)
Created: Fri Feb 04 16:32:13 2005
Last modified: Thu Feb 24 15:24:25 Central Standard Time 2005