Computer Sciences Dept.

Computer Security and Cryptography Reading Group
January 2005 List

Date &
Location
Reading
Monday, January 24, 2005
2:30 PM - 3:30 PM 3331 CS

Jun Xu
Frank Castañeda, Emre Can Sezer, Jun Xu
North Carolina State University
WORM vs. WORM: preliminary study of an active counter-attack mechanism
WORM'04

URL: http://doi.acm.org/10.1145/1029618.1029631

Self-propagating computer worms have been terrorizing the Internet for the last several years. With the increasing density, inter-connectivity and bandwidth of the Internet combined with security measures that inadequately scale, worms will continue to plague the Internet community. Existing anti-virus and intrusion detection systems are clearly inadequate to defend against many recent fast-spreading worms. In this paper we explore an active counter-attack method - anti-worms. We propose a method that transforms a malicious worm into an anti-worm which disinfects its original. The method is evaluated using the CodeRed, Blaster and Slammer worms. We show through simulation the effectiveness of an anti-worm with several propagation schemes and its impact on the overall network. We also discuss important limitations of the proposed method.


< Back to the Sec & Crypto reading group page
Created and maintained by Mihai Christodorescu (http://www.cs.wisc.edu/~mihai)
Created: Fri Feb 04 16:32:13 2005
Last modified: Thu Feb 24 15:24:25 Central Standard Time 2005
 
Computer Science | UW Home