Worm origin identification and propagation path reconstruction are essential problems in digital forensics. However, a small number of studies have specifically investigated these problems so far. In this paper, we extend a distributed trace-back algorithm, called Origins, which is only able to identify the origins of fast-spreading worms. We make some modifications to this algorithm so that in addition to identifying the worm origins, it can also reconstruct the propagation path. We also evaluate our extended algorithm. The results show that our algorithm can reconstruct the propagation path of worms with high recall and precision, on average around 0.96. Also, the algorithm identifies the origins correctly in all of our experiments.
翻译:虫源的识别和传播路径的重建是数字法证中的基本问题。 但是,目前只有少数研究专门调查了这些问题。 在本文中,我们推广了一种分布式的追踪算法,称为起源算法,它只能确定迅速蔓延的蠕虫的起源。我们对这一算法做了一些修改,以便除了确定蠕虫起源外,它还可以重建传播路径。我们还评估了我们的扩展算法。结果显示,我们的算法可以以高回溯和精确度重建蠕虫的传播路径,平均大约为 0.96。 另外,算法还确定了我们所有实验中正确的起源。