A Fast Worm Scan Detection Tool for VPN Congestion Avoidance
Arno Wagner,Thomas D¨ ubendorfer, Roman Hiestand, Christoph G¨
- ldi, Bernhard Plattner
Communication Systems Group Swiss Federal Institute of Technology Zurich (ETH Zurich)
A Fast Worm Scan Detection Tool for VPN Congestion Avoidance Arno - - PowerPoint PPT Presentation
A Fast Worm Scan Detection Tool for VPN Congestion Avoidance Arno Wagner,Thomas D ubendorfer, Roman Hiestand, Christoph G oldi, Bernhard Plattner Communication Systems Group Swiss Federal Institute of Technology Zurich (ETH Zurich)
Arno Wagner,Thomas D¨ ubendorfer, Roman Hiestand, Christoph G¨
Communication Systems Group Swiss Federal Institute of Technology Zurich (ETH Zurich)
Arno Wagner, ETH Zurich, DIMVA 2006 – p.1
Arno Wagner, ETH Zurich, DIMVA 2006 – p.2
Arno Wagner, ETH Zurich, DIMVA 2006 – p.3
Arno Wagner, ETH Zurich, DIMVA 2006 – p.4
Arno Wagner, ETH Zurich, DIMVA 2006 – p.5
Arno Wagner, ETH Zurich, DIMVA 2006 – p.6
< 5 minutes failed conn. in < 2 minutes TCP_BENIGN yes yes no first failed TCP connection no > 100 failed conn. TCP_SCAN to >100 hosts in
Arno Wagner, ETH Zurich, DIMVA 2006 – p.7
TCP_HOST_SCAN < 5 minutes failed conn. TCP_HOST_SAMEPORT_SCAN TCP_HOST_PORT_SCAN failed conn. yes yes yes yes no no no TCP_HOST_NOTSAMEPORT_SCAN WORM WORM no to >100 hosts in > 100 hosts on the same to > 300 hosts in < 5 min. DoS TCP_DOS
> 1200 failed TCP_SAMEPORT_SCAN < 4 min failed conn. to port in < 5 min.
TCP_BENIGN back to
Arno Wagner, ETH Zurich, DIMVA 2006 – p.8
Arno Wagner, ETH Zurich, DIMVA 2006 – p.9
Arno Wagner, ETH Zurich, DIMVA 2006 – p.10
Arno Wagner, ETH Zurich, DIMVA 2006 – p.11
Arno Wagner, ETH Zurich, DIMVA 2006 – p.12
1 1 2 3 4 5 6 7 8 9 10 cpu usage (%) time (min)
Arno Wagner, ETH Zurich, DIMVA 2006 – p.13
10 20 30 40 50 60 70 80 1 2 3 4 5 6 7 8 9 10 cpu usage (%) time (min)
Arno Wagner, ETH Zurich, DIMVA 2006 – p.14
Arno Wagner, ETH Zurich, DIMVA 2006 – p.15
Arno Wagner, ETH Zurich, DIMVA 2006 – p.16
Arno Wagner, ETH Zurich, DIMVA 2006 – p.17
Arno Wagner, ETH Zurich, DIMVA 2006 – p.18