TY - GEN
T1 - Optimum identification of worm-infected hosts
AU - Kamiyama, Noriaki
AU - Mori, Tatsuya
AU - Kawahara, Ryoichi
AU - Harada, Shigeaki
PY - 2008/11/28
Y1 - 2008/11/28
N2 - The authors have proposed a method of identifying superspreaders by flow sampling and a method of extracting worm-infected hosts from the identified superspreaders using a white list. However, the problem of how to optimally set parameters, φ, the measurement period length, m *, the identification threshold of the flow count m within φ, and H *, the identification probability for hosts with m∈=∈m *, remains unsolved. These three parameters seriously affect the worm-spreading property. In this paper, we propose a method of optimally designing these three parameters to satisfy the condition that the ratio of the number of active worm-infected hosts divided by the number of all the vulnerable hosts is bound by a given upper-limit during the time T required to develop a patch or an anti-worm vaccine.
AB - The authors have proposed a method of identifying superspreaders by flow sampling and a method of extracting worm-infected hosts from the identified superspreaders using a white list. However, the problem of how to optimally set parameters, φ, the measurement period length, m *, the identification threshold of the flow count m within φ, and H *, the identification probability for hosts with m∈=∈m *, remains unsolved. These three parameters seriously affect the worm-spreading property. In this paper, we propose a method of optimally designing these three parameters to satisfy the condition that the ratio of the number of active worm-infected hosts divided by the number of all the vulnerable hosts is bound by a given upper-limit during the time T required to develop a patch or an anti-worm vaccine.
KW - Detection
KW - Optimum design
KW - Sampling
KW - Worm
UR - http://www.scopus.com/inward/record.url?scp=56649111112&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=56649111112&partnerID=8YFLogxK
U2 - 10.1007/978-3-540-87357-0_9
DO - 10.1007/978-3-540-87357-0_9
M3 - Conference contribution
AN - SCOPUS:56649111112
SN - 3540873562
SN - 9783540873563
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 103
EP - 116
BT - IP Operations and Management - 8th IEEE International Workshop, IPOM 2008, Proceedings
T2 - 8th IEEE International Workshop on IP Operations and Management, IPOM 2008
Y2 - 22 September 2008 through 26 September 2008
ER -