Abstract
Traditional algorithm to scanning worms early warning cannot be used to distinguish P2P activity which can produce infection-like traffic, it also cannot be used to forecast the multi-vector worms which propagate by exploiting several vulnerabilities. To solve the problems, an improved algorithm is proposed by combine the analysis on Internet worm behavior. Finally, the feasibility and the properties of this method are analyzed by comparing with exiting methods. The new approach becomes more effective and can detect Internet worms at the early stage of worm propagation.