White Papers

Traffic Aggregation for Malware Detection

Category: Security

Tags: spyware, malware, network, data

Overview Stealthy malware, such as botnets and spyware, are hard to detect because their activities are subtle and do not disrupt the network, in contrast to DoS attacks and aggressive worms. Stealthy malware, however, does communicate to exfiltrate data to the attacker, to receive the attacker's commands, or to carry out those commands. Since malware rarely infiltrates only a single host in a large enterprise, these communications should emerge from multiple hosts within coarse temporal proximity to one another. This paper describes a system called TAMD (pronounced "Tamed") with which an enterprise can identify candidate groups of infected computers within its network. TAMD accomplishes this by finding new communication "Aggregates" involving multiple internal hosts, i.e., communication flows that share common characteristics.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Carnegie Mellon University
File Format
PDF
Date Published
Oct 22, 2008
Format
White Papers
Topics
Spyware, Network Security, Security Management

Similiar White Papers

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

According to recent surveys, employee social networking is growing rapidly, on hot sites such as Facebook, LinkedIn and

Publisher: MessageLabs, now part of Symantec  |  Tags: enterprise security, social networking

Sophos Email Security and Control - Free 30 Day Trial

Sophos Email Security and Control - Free 30 Day Trial

Proactively block inbound and outbound threats with unrivaled effectiveness and simplicity, delivering high-capacity, hi

Publisher: Sophos

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

The X-Force Threat Insight Quarterly (Threat IQ) highlights the most significant threats and challenges facing security

Publisher: Internet Security Systems  |  Tags: homeland security, security flaws, voip

Web Security SaaS: The Next Generation of Web Security

Web Security SaaS: The Next Generation of Web Security

The Web is the new threat vector of choice for hackers and cybercriminals to distribute malware and perpetrate identity

Publisher: Webroot Software  |  Tags: hackers, idc, malware, saas

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

This technical product evaluation is focused on the ISS VoIP-enabled Intrusion Prevention devices. These are built to su

Publisher: Internet Security Systems  |  Tags: voip

Carnegie Mellon University White Papers

Cyber Threats and the U S Economy

Cyber Threats and the U S Economy

The Internet has proven to be an engine that is driving a revolution in the way individuals and organizations conduct bu

Publisher: Carnegie Mellon University  |  Tags: network, research and development

SEAD: Secure Efficient Distance Vector Routing for Mobile Wireless Ad Hoc Networks

SEAD: Secure Efficient Distance Vector Routing for Mobile Wireless Ad Hoc Networks

An ad hoc network is a collection of wireless computers (nodes), communicating among themselves over possibly multihop p

Publisher: Carnegie Mellon University  |  Tags: cpu, infrastructure, network

Packet Leashes: A Defense Against Wormhole Attacks in Wireless Networks

Packet Leashes: A Defense Against Wormhole Attacks in Wireless Networks

As mobile ad hoc network applications are deployed, security emerges as a central requirement. This paper introduces the

Publisher: Carnegie Mellon University  |  Tags: applications, network, wireless networks, wireless security

Verification of RSTP Convergence and Scalability by Measurements and Simulations

Verification of RSTP Convergence and Scalability by Measurements and Simulations

As the Ethernet technology is growing out from the LAN environment, its restoration and scalability properties are getti

Publisher: Carnegie Mellon University  |  Tags: ethernet, network

Counter-Forensic Tools: Analysis and Data Recovery

Counter-Forensic Tools: Analysis and Data Recovery

Among the challenges faced by forensic analysts are a range of commercial 'Disk scrubbers', software packages designed t

Publisher: Carnegie Mellon University  |  Tags: data, fingerprints, software