The PDF file you selected should load here if your Web browser has a PDF reader plug-in installed (for example, a recent version of Adobe Acrobat Reader).

If you would like more information about how to print, save, and work with PDFs, Highwire Press provides a helpful Frequently Asked Questions about PDFs.

Alternatively, you can download the PDF file directly to your computer, from where it can be opened using a PDF reader. To download the PDF, click the Download link above.

Fullscreen Fullscreen Off


A worm is a self-propagating, self-duplicating malicious code that spread without human intervention in computer networks and attacks vulnerable hosts. The severity of network worms depends on the propagation process that degrades the network performance and consume bandwidth and resource (CPU and memory). Thus, this paper presents a behavioral approach for UDP worm (worm uses UDP as transmission mechanism) detection based on scanning and Destination Source Correlation (DSC) behaviors of worm. The proposed approach consists of two sub approaches which are: 1. Statistical Cross-relation Approach for Network Scanning detection (SCANS) approach that is used to detect the presence of network scanning behavior of worm and 2. Worm correlation approach that is used to detect Destination-Source Correlation (DSC) behavior of worm. These behaviors have been chosen among other worm behaviors due to its anomaly behaviors that are clearly exhibit in the network. A salient feature of this approach is that it effective for detecting scanning DSC behaviors of worm with high accuracy. The proposed approach is evaluated with the simulated dataset obtained from Georgia Tech Network Simulator (GTNetS) simulator and confirmed that our approach is efficient in detecting UDP worm than the existing approach.

Keywords

Behavioural based Approach, UDP Worm Detection, UDP Worm
User