Information and Media Technologies
Online ISSN : 1881-0896
ISSN-L : 1881-0896
Computing
d-ACTM/VT: A Distributed Virtual AC Tree Detection Method
Nobutaka KawaguchiHiroshi ShigenoKen-ichi Okada
著者情報
ジャーナル フリー

2008 年 3 巻 2 号 p. 246-257

詳細
抄録
In this paper, we propose d-ACTM/VT, a network-based worm detection method that effectively detects hit-list worms using distributed virtual AC tree detection. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. To address this problem, d-ACTM/VT aggregates the divided trees as a tree named Virtual AC tree in a distributed manner and utilizes the tree size for detection. Simulation result shows d-ACTM/VT reduces the number of infected hosts before detection by 20% compared to d-ACTM.
著者関連情報
© 2008 by Information Processing Society of Japan
前の記事 次の記事
feedback
Top