TY - GEN
T1 - Multi-packet signature detection using prefix bloom filters
AU - Artan, N. Sertac
AU - Chao, H. Jonathan
PY - 2005
Y1 - 2005
N2 - It is now a fact that manual defenses against worm epidemics are not practical. Recently, various automatic worm identification methods are proposed to be deployed at highspeed network nodes to respond in time to fast infection rates of worms. Unfortunately, these methods can easily be evaded by fragmentation of the worm packets. The straightforward defragmentation method is not applicable for these high-speed nodes, due to its high storage (memory) requirement. In this paper, this problem, namely the multi-packet signature detection problem is addressed using a defragmentation-free, spaceefficient solution. A new data structure - Prefix Bloom Filters along with a new heuristic, called the chain heuristic is proposed to significantly reduce the storage requirement of the problem, so that multi-packet signature detection becomes feasible for highspeed network nodes.
AB - It is now a fact that manual defenses against worm epidemics are not practical. Recently, various automatic worm identification methods are proposed to be deployed at highspeed network nodes to respond in time to fast infection rates of worms. Unfortunately, these methods can easily be evaded by fragmentation of the worm packets. The straightforward defragmentation method is not applicable for these high-speed nodes, due to its high storage (memory) requirement. In this paper, this problem, namely the multi-packet signature detection problem is addressed using a defragmentation-free, spaceefficient solution. A new data structure - Prefix Bloom Filters along with a new heuristic, called the chain heuristic is proposed to significantly reduce the storage requirement of the problem, so that multi-packet signature detection becomes feasible for highspeed network nodes.
UR - http://www.scopus.com/inward/record.url?scp=33846612446&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33846612446&partnerID=8YFLogxK
U2 - 10.1109/GLOCOM.2005.1577961
DO - 10.1109/GLOCOM.2005.1577961
M3 - Conference contribution
AN - SCOPUS:33846612446
SN - 0780394143
SN - 9780780394148
T3 - GLOBECOM - IEEE Global Telecommunications Conference
SP - 1811
EP - 1816
BT - GLOBECOM'05
T2 - GLOBECOM'05: IEEE Global Telecommunications Conference, 2005
Y2 - 28 November 2005 through 2 December 2005
ER -