TY - GEN
T1 - FDF
T2 - 2006 IEEE International Conference on Communications, ICC 2006
AU - Kim, Byungseung
AU - Bahk, Saewoong
AU - Kim, Hyogon
PY - 2006
Y1 - 2006
N2 - In this paper, we propose a simple algorithm for detecting scanning worms with high detection rate and low false positive rate. The novelty of our algorithm is inspecting the frequency characteristic of scanning worms from a monitored network. Its low complexity allows it to be used on any networkbased intrusion detection system as a real time detection module for high-speed networks. Our algorithm need not be adjusted to network status because its parameters depend on application types, which are generally and widely used in any networks such as web and P2P services. By using real traces, we evaluate the performance of our algorithm and compare it with that of SNORT. The results confirm that our algorithm outperforms SNORT with respect to detection rate and false positive rate.
AB - In this paper, we propose a simple algorithm for detecting scanning worms with high detection rate and low false positive rate. The novelty of our algorithm is inspecting the frequency characteristic of scanning worms from a monitored network. Its low complexity allows it to be used on any networkbased intrusion detection system as a real time detection module for high-speed networks. Our algorithm need not be adjusted to network status because its parameters depend on application types, which are generally and widely used in any networks such as web and P2P services. By using real traces, we evaluate the performance of our algorithm and compare it with that of SNORT. The results confirm that our algorithm outperforms SNORT with respect to detection rate and false positive rate.
UR - http://www.scopus.com/inward/record.url?scp=42549117686&partnerID=8YFLogxK
U2 - 10.1109/ICC.2006.255084
DO - 10.1109/ICC.2006.255084
M3 - Conference contribution
AN - SCOPUS:42549117686
SN - 1424403553
SN - 9781424403554
T3 - IEEE International Conference on Communications
SP - 2124
EP - 2129
BT - 2006 IEEE International Conference on Communications, ICC 2006
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 11 July 2006 through 15 July 2006
ER -