Skip to main navigation Skip to search Skip to main content

Blue-watchdog: Detecting bluetooth worm propagation in public areas

  • Guanhua Yan
  • , Leticia Cuellar
  • , Stephan Eidenbenz
  • , Nicolas Hengartner

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

The rising popularity of mobile devices, such as cellular phones and PDAs, has made them a lucrative playground for mobile malware propagation. One common infection vector exploited by these mobile malware is Bluetooth. In this paper, we propose an architecture called Blue-Watchdog that detects Bluetooth worm propagation in public areas based on statistical methods. To achieve fast and accurate Bluetooth worm detection, Blue-Watchdog monitors abrupt changes of average paging rate per Bluetooth device from both temporal and temporal-spatial perspectives. The temporal scheme relies on the CUSUM (Cumulative Sum) sequential test together with the generalized likelihood ratio (GLR), and the temporal-spatial scheme aims to identify spatial regions with abnormally frequent paging attempts. Experimental results show that Blue-Watchdog not only has low false alarm rates, but also effectively detects Bluetooth worms that spread quickly in areas where Bluetooth devices are greatly mixed due to high mobility and also those that propagate relatively slowly in a spatially constrained fashion.

Original languageEnglish
Title of host publicationProceedings of the 2009 IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2009
Pages317-326
Number of pages10
DOIs
StatePublished - 2009
Event2009 IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2009 - Lisbon, Portugal
Duration: Jun 29 2009Jul 2 2009

Publication series

NameProceedings of the International Conference on Dependable Systems and Networks

Conference

Conference2009 IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2009
Country/TerritoryPortugal
CityLisbon
Period06/29/0907/2/09

Keywords

  • Bluetooth
  • Bluetooth worms
  • CUSUM
  • Temporal detection
  • Temporal-spatial detection

Fingerprint

Dive into the research topics of 'Blue-watchdog: Detecting bluetooth worm propagation in public areas'. Together they form a unique fingerprint.

Cite this