ダミーアドレスを用いた電子メール型ワームの感染源特定支援手法の検討

書誌事項

タイトル別名
  • A support system for detection of infection source node of e-mail worm using dummy addresses
  • ダミーアドレス オ モチイタ デンシ メールガタ ワーム ノ カンセン ゲン トクテイ シエン シュホウ ノ ケントウ

この論文をさがす

抄録

The "e-mail worm" is a kind of the worm which infects using internal address information. Huang et al. proposed a detection method of e-mail worms using the "dummy address" which is randomly generated by the system. In this system, it is possible to detect some worms but not able to find the node of infection source. In this paper, we propose a system for detection of infection source node of e-mail worm. In the proposed system, the "black list" which includes the information of influenced nodes that accessed one of the dummy addresses is introduced. Then a graph which shows a flow of influence in the network is generated by using communication log of e-mails. We can estimate the infection source node of e-mail worm from the structured graph.

収録刊行物

関連プロジェクト

もっと見る

キーワード

詳細情報 詳細情報について

問題の指摘

ページトップへ