Information and Media Technologies
Online ISSN : 1881-0896
ISSN-L : 1881-0896
Computer Networks and Broadcasting
A Combinatorics Proliferation Model with Threshold for Malware Countermeasure
Kazumasa OmoteTakeshi ShimoyamaSatoru Torii
著者情報
ジャーナル フリー

2010 年 5 巻 2 号 p. 765-775

詳細
抄録
Security software such as anti-virus software and personal firewall are usually installed in every host within an enterprise network. There are mainly two kinds of security software: signature-based software and anomaly-based software. Anomaly-based software generally has a “threshold” that discriminates between normal traffic and malware communications in network traffic observation. Such a threshold involves the number of packets used for behavior checking by the anomaly-based software. Also, it indicates the number of packets sent from an infected host before the infected host is contained. In this paper, we propose a mathematical model that uses discrete mathematics known as combinatorics, which is suitable for situations in which there are a small number of infected hosts. Our model can estimate the threshold at which the number of infected hosts can be suppressed to a small number. The result from our model fits very well with the result of computer simulation using typical existing scanning malware and a typical network.
著者関連情報
© 2010 by Information Processing Society of Japan
前の記事 次の記事
feedback
Top