IPSJ Digital Courier
Online ISSN : 1349-7456
ISSN-L : 1349-7456
d-ACTM/VT: A Distributed Virtual AC Tree Detection Method
Nobutaka KawaguchiHiroshi ShigenoKen-ichi Okada
Author information
JOURNAL FREE ACCESS

2008 Volume 4 Pages 79-90

Details
Abstract

In this paper, we propose d-ACTM/VT, a network-based worm detection method that effectively detects hit-list worms using distributed virtual AC tree detection. To detect a kind of hit-list worms named Silent worms in a distributed manner, d-ACTM was proposed. d-ACTM detects the existence of worms by detecting tree structures composed of infection connections as edges. Some undetected infection connections, however, can divide the tree structures into small trees and degrade the detection performance. To address this problem, d-ACTM/VT aggregates the divided trees as a tree named Virtual AC tree in a distributed manner and utilizes the tree size for detection. Simulation result shows d-ACTM/VT reduces the number of infected hosts before detection by 20% compared to d-ACTM.

Content from these authors
© 2008 by the Information Processing Society of Japan
Previous article Next article
feedback
Top