Browse > Article

Simulation and Analysis of Slammer Worm Propagation With Automatic Quarantine  

Lim, Jae-Myung (한국항공대학교 정보통신공학과 대학원)
Jung, Han-Gyun (한국항공대학교 정보통신공학과)
Yoon, Chong-Ho (한국항공대학교 항공전자정보 통신공학부)
Abstract
In this paper, we have analyzed a simulation model of Slammer worm propagation process which caused serious disruptions on the Internet in the year of 2003 by using NS-2. Previously we had presented and analyzed Abstract Network to Abstract Network(AN-AN) model being modified from the Detailed Network to Abstract Network(DN-AN) of NS-2. However, packet analysis in AN-AN model had a problem of taking 240 hours to simulate the initial 300 seconds of infection. We have reduced the AN-AN model to save the simulation time and analyzed total 3.5 hours of the network congestions within 107 hours. Moreover, we have derived optimal quarantine rate of 0.0022 considering service outage of network devices caused by the heavy infected traffics, which was not taken into consideration in previous works. As the result of simulation, Although the inbound traffic at the Korean international gateway was back in normal conditions at 4,787 second, due to the revese direction saturation was maintained until 12,600 seconds, the service outage was persisted for 3.5 hours.
Keywords
Slammer; Worm Model; Worm-propagation; NS-2 Simulation; SIR Model;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 David Moore, et al., 'The Spread of the Sapphire/ Slammer Worm.' available at http://www.caida.org/ publications/ papers/2003/sapphire/sapphire.html
2 Stefan Misslinger, 'Internet Worm Propagation,' Technische University Munchen, 2003
3 Kevin Fall, Kannan Varadhan, 'The ns Manual'
4 S. Staniford, V. Paxson, N. Weaver, 'How to 0wn the internetin your spare time,' Proceedings of the 11th USENIX Security Symposium (Security '02), 2002
5 'Analysis of the Sapphire Worm.' A joint effort of CAIDA, ICSI, Silicon Defense, UC Berkeley EECS and UC San Diego, 2003
6 주요국내외정보화현황(2004년)
7 '정보통신망 침해사고 조사결과,' 정보통신망 침해 사고 합동조사단, 2003. 2
8 C.Onwubiko et al., 'An Improved Worm Mitigation Model for Evaluating the Spread of Aggressive Network Worms,' Serbia & Montenegro, Belagrade, Nov, 2005
9 David Moore, et al., 'Inside the slammer worm,' IEEE Magazine of Security and Privacy, pp. 33-39, July/ Aug. 2003
10 정보통신부, 유.무선 통신서비스 가입자 현황 (2003년1월)
11 임재명, 윤종호, '슬래머 웜 전파과정 분석을 위 한 네트워크 모델링 및 시뮬레이터 구현', 통신 공학회지, 2007. Vol.32   과학기술학회마을
12 C.C.Zou, W.Gong, and D.Towsley, 'Worm Propagation Modeling and Analysis under Dynamic Quarantine Defense,' WORM'03, Washington, 2003. ACM 1- 58113-785-0/03/0010, October 27, 2003
13 2003 한국인터넷백서, 한국전산원