Home

Research

Software

People

News

Contact Us

Internet Worm Detection Research, funded by an NSF CAREER grant and a grant from Intel

Internet worms have resulted in considerable disruption of our communications infrastructure. The combined cost of the Code Red and Sapphire/Slammer worms has been estimated at over three billion dollars, and these and other worms prevented the normal operation of the Internet and other networks.

Our primary focus is on limiting the possible damage from as-yet-unknown "0-day" worms. We have designed a behavior-based worm detection system, SWORD (Self-propagating Worm Observation and Rapid Detection). It focuses on major and essential aspects of worm connections that cross the gateway of an administrative domain.

In order to facilitate the testing of our detector, we have implemented a worm simulator, GLOWS (Gateway-Level Oregon Worm Simulator), capable of simulating a broad range of worm types and parameters.

Our publications and relevant documents include the following:

This material is based upon work supported by the National Science Foundation under Grant No. 0644434. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation.