A Self-Learning Worm Using Importance Scanning
INTRODUCTION
A worm attacks vulnerable computer systems and employs self-propagating method to flood the Internet rapidly Worms, such as Code Red [10], Slammer [9], and Witty [17], have infected hundreds of thousands of hosts and become a significant threat to network security and management. It is therefore of great importance for defenders to characterize the spread of worms that employ distinct scanning methods and to study countermeasures accordingly.
Different scanning methods have been employed by previous worms. For instance, Morris worm used topological scanning that relies on the information contained in the victim
host to find new targets. Code Red v2 and Slammer worms employed random scanning that selects targets randomly. Code Red II and Nimda worms exercised localized scanning that preferentially searches for targets on the “local” address space.