Statistics Analysis of Malicious Code Based Attack Flows Targeting Information Systems of Computer InfoSphere


A.Yu. Dobrodeyev, A.V. Gorshkov, U.M. Tulemisov

Analyzed are characteristics of flow of attacks by recent malicious codes including following types: virus, trojan and worms. The attacks analyzed were performed during time period 2007-2009. Characteristics analysis method of ordinary flow of random events is described in the article and is a basis of the study. Method includes preparatory phase: study of distribution of intervals between random events and characteristics study of the flow of random events. And additional phase of more detailed analysis. Following and according to this method attack flow analysis was conducted using program-analytical system of Samarky State Aero-cosmic University (department of Information Systems and Technologies). Approximation of non-normalized sampling theoretical density of distribution (time interval between attacks) was conducted as well. Conclusions are made about gained statistical characteristics of real flow of attacks (recent malicious codes) which can be utilized to improve attack prevention techniques and systems

