作者
Y-H Choi, Lunquan Li, Peng Liu, George Kesidis
发表日期
2010/2/1
期刊
computers & security
卷号
29
期号
1
页码范围
104-123
出版商
Elsevier Advanced Technology
简介
A worm-infected host scanning globally may not cause any new infection in its underlying local network before it is detected and quarantined by a worm detector. To defend this type of scanning hosts, a number of worm scanner detection methods such as failed scan detection, honeypot, and dark port detection are proposed. However, for a stealthier worm limiting its scan inside an enterprise network, the chance of a successful local outbreak increases substantively due to the more limited scan space. To protect a local or enterprise network against a local outbreak, we need a coordinated and cost-conscious defense that entails an accurate estimate of worm virulence level. Unfortunately, many existing defense methods suffer from estimating the worm virulence level in a local or enterprise network. In this regard, we propose a maximum likelihood estimator to progressively estimate the size of susceptible host …
引用总数
20102011201220132014201520162017201820192020202120221312111
学术搜索中的文章