CERIAS Tech Report 2005-81 CSD TR #05-028 PROVENANCE-AWARE TRACING OF WORM BREAK-IN AND CONTAMINATIONS: A PROCESS COLORING APPROACH

نویسندگان

  • Xuxian Jiang
  • Aaron Walters
  • Florian Buchholz
  • Dongyan Xu
  • Yi-Min Wang
  • Eugene H. Spafford
چکیده

To investigate the exploitation and contamination by self-propagating Internet worms, a provenanceaware tracing mechanism is highly desirable. Provenance unawareness causes difficulties in fast and accurate identification of a worm’s break-in point (namely, a remotely-accessible vulnerable service running in the infected host), and incurs significant log data inspection overhead. This paper presents the design, implementation, and evaluation of process coloring, an efficient provenance-aware approach to worm breakin and contamination tracing. More specifically, process coloring assigns a “color”, a unique system-wide identifier, to each remotely-accessible server or process. The color will then be either inherited by spawned child processes or diffused indirectly through process actions (e.g., read or write operations). Process coloring brings two major advantages: (1) It enables fast color-based identification of the break-in point exploited by a worm even before detailed log analysis; (2) It naturally partitions log data according to their associated colors, effectively reducing the volume of log data that need to be examined and correspondingly, log processing overhead for worm investigation. A tamper-resistant log collection method is developed based on the virtual machine introspection technique. Our experiments with a number of real-world worms demonstrate the advantages of processing coloring. For example, to reveal detailed SARS worm contamination, only 12.1% of the entire log data need to be processed. Beyond the virtual machine platform of our prototype, process coloring and logging mechanisms only incur a very small additional performance penalty.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

بررسی آلودگیهای هوازی چهار ماده مصرفی (گوتاپرکا، ساکشن، کارپول و رول‌پنبه)

Statement of Problem: Today, cross infection control is an integral part of dentistry and many dental health care workers no longer question its necessity. All dental equipments and instruments could be potentially considered as a source of infection. Purpose: The aim of this study was the evaluation of aerobic contaminations of four disposable materials used in routine dental practice. Materia...

متن کامل

Contaminations in genomic sequences

Despite continued advances in whole genome sequencing techniques and the development of powerful assembly algorithms, newly sequenced genomes still often suffer from contaminations during the sequencing process. The most common sources of contamination are accessory DNAs deliberately attached to the DNA/RNA under investigation, including vectors, adapters, linkers and PCR primers. However, ther...

متن کامل

Sugarcane transportation process modeling by time series approach

Sugarcane is one of the severely perishable crops that is used as raw material for white sugar production. Sucrose content of the sugarcane which is of high commercial value decreases in quality due to pre-harvest burning, high ambient temperature, kill-to-mill delays as well as microbial contaminations. Delays in sugarcane transportation are the most important risks which can affect the qualit...

متن کامل

Effect of Infrared Roasting Process on the Microorganism Contaminations of Long and Round Iranian Pistachio Kernels

In this paper, the effect of infrared (IR) roasting conditions on Aflatoxins and total counts of two types of Iranian pistachio kernels, long and round, was studied. The optimized roasting conditions, 70 V for round pistachios and 90 V for long pistachios with 10 cm distance from IR source were used. Naturally Aflatoxin-contaminated kernels were supplied and roasted. Microbiological an...

متن کامل

Eradication of mycoplasma contaminations.

Mycoplasma contaminations have a multitude of effects on the cultured cell lines that may influence the results of experiments or pollute bioactive substances used in human medicine. The elimination of mycoplasma contaminations of cell cultures has become a practical alternative to discarding and reestablishing important or irreplaceable cell lines. Different quinolones, tetracyclines, and pleu...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005