[Paper Review] An Information-Theoretical View of Network-Aware Malware Attacks
This paper introduces an information-theoretic framework to analyze network-aware malware propagation by quantifying the impact of non-uniform vulnerable-host distributions using Renyi entropy. It shows that network-aware malwares can achieve infection rates nearly a non-uniformity factor faster than random scanners, and that defenses like host-based protection and IPv6 offer limited resistance when vulnerable hosts remain clustered.
This work investigates three aspects: (a) a network vulnerability as the non-uniform vulnerable-host distribution, (b) threats, i.e., intelligent malwares that exploit such a vulnerability, and (c) defense, i.e., challenges for fighting the threats. We first study five large data sets and observe consistent clustered vulnerable-host distributions. We then present a new metric, referred to as the non-uniformity factor, which quantifies the unevenness of a vulnerable-host distribution. This metric is essentially the Renyi information entropy and better characterizes the non-uniformity of a distribution than the Shannon entropy. Next, we analyze the propagation speed of network-aware malwares in view of information theory. In particular, we draw a relationship between Renyi entropies and randomized epidemic malware-scanning algorithms. We find that the infection rates of malware-scanning methods are characterized by the Renyi entropies that relate to the information bits in a non-unform vulnerable-host distribution extracted by a randomized scanning algorithm. Meanwhile, we show that a representative network-aware malware can increase the spreading speed by exactly or nearly a non-uniformity factor when compared to a random-scanning malware at an early stage of malware propagation. This quantifies that how much more rapidly the Internet can be infected at the early stage when a malware exploits an uneven vulnerable-host distribution as a network-wide vulnerability. Furthermore, we analyze the effectiveness of defense strategies on the spread of network-aware malwares. Our results demonstrate that counteracting network-aware malwares is a significant challenge for the strategies that include host-based defense and IPv6.
Motivation & Objective
- To understand how non-uniform distributions of vulnerable hosts create exploitable network vulnerabilities.
- To quantify the relationship between vulnerable-host distribution unevenness and malware propagation speed using information theory.
- To evaluate the effectiveness of common defense strategies—like host-based protection and IPv6—against network-aware malwares.
- To demonstrate that network-aware malwares can achieve near-optimal infection rates by exploiting distribution non-uniformity.
Proposed method
- The non-uniformity factor is defined as the Renyi entropy of order two, which quantifies the unevenness of vulnerable-host distributions more effectively than Shannon entropy.
- The paper models malware scanning as a randomized epidemic process and relates infection rates to Renyi entropies of different orders.
- Analytical expressions are derived linking infection rates of network-aware malwares to the uncertainty (Renyi entropy) in locating vulnerable hosts.
- Empirical data from five large-scale measurements are used to compute non-uniformity factors, showing consistently high values across diverse networks and applications.
- The model is validated by comparing infection rates of localized scanning and modified sequential scanning to random scanning, showing near-ideal performance gains.
- The impact of IPv6 on malware spread is analyzed by extrapolating subnetwork infection rates, showing that IPv6 does not inherently slow down network-aware malwares if clustering persists.
Experimental results
Research questions
- RQ1How can the unevenness of vulnerable-host distributions be quantified in a way that reflects their impact on malware propagation?
- RQ2To what extent do network-aware malwares outperform random-scanning malwares in terms of infection speed?
- RQ3How do different randomized scanning algorithms relate to information-theoretic measures like Renyi entropy?
- RQ4Can host-based defenses or IPv6 deployment effectively mitigate the threat of network-aware malwares?
- RQ5What is the theoretical upper bound on malware infection speed when exploiting non-uniform vulnerable-host distributions?
Key findings
- The non-uniformity factor, based on Renyi entropy of order two, consistently shows high values across five empirical data sets, indicating significant clustering of vulnerable hosts.
- Network-aware malwares can increase their infection rate by nearly the non-uniformity factor compared to random-scanning malwares at the early stage of propagation.
- Localized scanning and modified sequential scanning achieve infection rates close to that of optimal importance scanning, demonstrating near-optimality in exploiting distribution non-uniformity.
- The infection rate of a /32 intelligent scanner in IPv6 is estimated at 2.2×10⁻³ per second, exceeding that of the Code Red v2 worm in IPv4 (5×10⁻⁴), showing IPv6 does not inherently slow down such threats.
- Host-based defenses require near-complete deployment to be effective, and IPv6 offers little resistance if vulnerable hosts remain clustered, making network-aware malwares potentially zero-day threats in IPv6.
- The information-theoretic framework successfully links the information bits extracted from vulnerable-host distributions to the actual propagation speed of malwares.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.