Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs
• SEI Report
Publisher
Software Engineering Institute
Topic or Tag
Abstract
We present a novel method for detecting hit-list worms using protocol graphs. In a protocol graph, a vertex represents a single IP address, and an edge represents communications between those addresses using a specific protocol (e.g., HTTP). We show that the protocol graphs of four diverse and representative protocols (HTTP, FTP, SMTP, and Oracle), as constructed from monitoring for fixed durations on a large intercontinental network, exhibit stable graph sizes and largest connected component sizes. Moreover, we demonstrate that worm propagations, even of a sophisticated hit-list variety in which the attacker has advance knowledge of his targets and always connects successfully, perturb these properties. We demonstrate that these properties can be monitored very efficiently even in very large networks, giving rise to a viable and novel approach for worm detection. We also demonstrate extensions by which the attacking hosts (bots) can be identified with high accuracy.
Cite This SEI Report
Collins, M., & Reiter, M. (2007, September 5). Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs. Retrieved September 12, 2026, from https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/.
@techreport{collins_2007,
author={Collins, M. and Reiter, Michael},
title={Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs},
month={Sep},
year={2007},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/},
note={Accessed: 2026-Sep-12}
}
Collins, M., and Michael Reiter. "Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, September 5, 2007. https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/.
M. Collins, and M. Reiter, "Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 5-Sep-2007 [Online]. Available: https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/. [Accessed: 12-Sep-2026].
Collins, M., and Michael Reiter. "Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 5 Sep. 2007. https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/. Accessed 12 Sep. 2026.
Collins, M.; & Reiter, Michael. Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs. Software Engineering Institute. 2007. https://www.sei.cmu.edu/library/hit-list-worm-detection-and-bot-identification-in-large-networks-using-protocol-graphs/
This content was created for a conference series or symposium and does not necessarily reflect the positions and views of the Software Engineering Institute.