Abstract:
activities to model and analyze Internet worm propagation. In this paper we provide a careful analysis of Code Red propagation by accounting for two factors: one is the dynamic countermeasures taken by ISPs and users; the other is the slowed down worm infection rate because Code Red rampant propagation caused congestion and troubles to some routers. Based on the classical epidemic Kermack-Mckendrick model, we derive a general Internet worm model called the twofactor worm model. Simulations and numerical solutions of the two-factor worm model match the observed data of Code Red worm better than previous models do. This model leads to a better understanding and prediction of the scale and speed of Internet worm spreading.
Citations
|
127
|
The mathematical theory of infectious diseases and its applications
– Bailey
- 1975
|
|
74
|
Infectious Diseases of Humans: Dynamics and Control
– Anderson, May
- 1991
|
|
63
|
Observation and analysis of bgp behavior under stress
– Wang
- 2002
|
|
54
|
Directed-graph epidemiological models of computer viruses
– Kephart, White
- 1991
|
|
50
|
How to Own the Internet
– Staniford, Paxson, et al.
- 2002
|
|
48
|
Measuring and modeling computer virus prevalence, in
– Kephart, White
- 1993
|
|
35
|
Computers and epidemiology
– Kephart, White
- 1993
|
|
24
|
Worms: The Potential for Very Fast Internet Plagues, http://www. cs.berkeley.edu/˜nweaver/warhol.html
– Weaver, Warhol
- 2001
|
|
19
|
Global routing instabilities during Code Red II and Nimda worm propagation
– Cowie, Ogielski, et al.
- 2001
|
|
19
|
The Internet Worm Incident
– Spafford
- 1991
|
|
17
|
Stochastic Epidemic Models and their Statistical Analysis
– Andersson, Britton
- 2001
|
|
13
|
Mathematical Modeling in Epidemiology
– Frauenthal
- 1980
|
|
9
|
Fluid based analysis of a network of AQM routers supporting TCP flows with an application to RED
– Misra, Gong, et al.
- 2000
|
|
8
|
On Viral Propagation and the Effect of Immunization
– Wang, Knight, et al.
- 2000
|
|
3
|
The Spread of the Code-Red Worm
– Moore
|
|
2
|
The Evolving Virus Threat
– Nachenberg
- 2000
|
|
1
|
Security Advisory: “Code Red
– Cisco
|
|
1
|
notes: Dealing with mallocfail and High CPU Utilization Resulting From the “Code Red” Worm. http://www.cisco.com/warp/public/63/ ts codred worm.shtml
– Tech
|
|
1
|
Visual simulation of Code Red worm propagation patterns
– Heberlein
|
|
1
|
Virulent worm calls into doubt our ability to protect the Net
– Lemos
|
|
1
|
Microsoft reveals Web server hole
– Lemos
|