An approach for classifying internet worms based on temporal behaviors and packet flows

Min-Soo Lee, Taeshik Shon, Kyuhyung Cho, Manhyun Chung, Jungtaek Seo, Jongsub Moon

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    2 Citations (Scopus)

    Abstract

    With the growth of critical worm threats, many researchers have studied worm-related topics and internet anomalies. The researches are mainly concentrated on worm propagation and detection more than the fundamental characteristics of worms. It is very important to know worms' characteristics because the characteristics provide basic resource for worm prevention. Unfortunately, this kind of research cases are very few until now. Moreover the existing researches only focus on understanding the function structure of the worm propagation or the taxonomy of the worm according to a sequence of worm attacks. Thus, in this paper, we try to confirm the formalized pattern of the worm action from the existing researches and analyze the report of the anti-virus companies. Finally, we define the formalized actions based on temporal behaviors and worm packet flows, and we apply our proposed method for the new worm classification.

    Original languageEnglish
    Title of host publicationAdvanced Intelligent Computing Theories and Applications
    Subtitle of host publicationWith Aspects of Theoretical and Methodological Issues - Third International Conference on Intelligent Computing, ICIC 2007, Proceedings
    Pages646-655
    Number of pages10
    Volume4681 LNCS
    Publication statusPublished - 2007 Dec 1
    Event3rd International Conference on Intelligent Computing, ICIC 2007 - Qingdao, China
    Duration: 2007 Aug 212007 Aug 24

    Publication series

    NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
    Volume4681 LNCS
    ISSN (Print)0302-9743
    ISSN (Electronic)1611-3349

    Other

    Other3rd International Conference on Intelligent Computing, ICIC 2007
    Country/TerritoryChina
    CityQingdao
    Period07/8/2107/8/24

    Keywords

    • Taxonomy of worm
    • Temporal behavior
    • Ubiquitous security
    • Worm packet flows

    ASJC Scopus subject areas

    • Theoretical Computer Science
    • Computer Science(all)

    Fingerprint

    Dive into the research topics of 'An approach for classifying internet worms based on temporal behaviors and packet flows'. Together they form a unique fingerprint.

    Cite this