This paper addresses self-propagating malware, particularly internet worms, and proposes a novel solution to limit their spread based on observed connection failure rates. It identifies flaws in previous measuring methods, particularly the use of ICMP messages that are often blocked, and introduces a double-bitmap data structure for more efficient and accurate measurement of these failure rates. The findings illustrate that this method not only requires minimal memory but also allows for tuning the accuracy of connection failure measurements.