George and Vincent proposed an early warning system that uses ICMP Destination Unreachable messages to detect random scanning worms in [1]. Such worm is not detected in previous phases because the distribution of the addresses targeted by worm is not different from normal profile. Table 3: Distinct Destination IP Number in 10:00 am in POSTECH Inbound Traffic Destination TCP Port 4662 5000 8080 445 139 135 80 25 Distinct Destination IP 23 3117 0 2156

Unused Destination IP Random scan is the most popular technique in previous active worms. In our study, we focus on the following objectives. - identifying hosts with scanning activity in local network - detecting worm propagation activities with a low false positive error The first The method using the Kalman filter is suitable to detect worm in its starting stage on the network without worm infected. As we mentioned in 4.4, by that process, we have 7 suspicious destination ports.

  3. On the other hand, once a host in a local network is infected by a worm, all worm scans generated from it can be monitored.

The start time is the timestamp of the earliest packet in the interval, and the end time is the latest one. This process is illustrated in Figure 1. The related work about worm detection or similar studies is discussed in Section 2. When selecting target hosts, worms use a kind of scanning strategies.

In [11], Wu et. To validate our algorithm, we have gathered traffic traces in our campus backbone network and analyzed the traffic containing many worm activities.

Our monitoring algorithm presents an easy method to distinguish worm traffic in the router junction of enterprise network.

The backdoor ports that the Beagle and Mydoom families of worms open. Overall process of our algorithm is described below. In self-contained chapters that go into varying degrees of depth, the book provides a thorough overview of crimeware, including not only concepts prevalent in the wild, but also ideas that so

Gao, and K. In contrast with TCP, there is not a connection establishment process in UDP. A difference between worm and normal traffic is that the destination address of a connection-request packet generated by a worm can be an unused IP address. If the scan rate is over a threshold related with worm’s target port, we regard the source address of the record as the suspicious host, and the record is included among

To this process, we have detected 75 hosts in POSTECH been infected by worm. Our goals are to accurately identify infected hosts in local network and detect worm propagation activity with low false alarms.

Except that its target addresses are reduced from whole internet address size, 232, to around 109 [11], its activity is same as a random scan worm. TCP port 80 is a typical port that there exist both normal and abnormal data. Except five hosts on destination port 4662, generate connection request packets to unused IP address.