In this paper, concepts of Worm Poisoning and PoisonWorm are presented and the feasibility of Worm Poisoning is testified. A propagation model named SIRP Model and PoisonWorm?s side-effect on network traffic are given and compared with the classical epidemic Kermack-Mckendrick model. The feasibility and necessity of PoisonWorm and its application are highlighted in an active defense system against Internet worms. In addition, the technology of P2P-based unknown worm detection and signature verification are introduced briefly.
Citation:
Bing Wu, Xiaochun Yun, Xiang Cui, "Study on Worm Poisoning Technology," itng, pp.65-70, International Conference on Information Technology (ITNG'07), 2007