Following the development of Internet and the improvement of network services, network malicious code, delegated by worms, has become a major threat to peoples normal life. The research work related to worm detection is urgent but difficult. In this paper, we present a worm trend early detection method based on the long-range dependence (LRD) analysis of scan traffic entering the monitored network. Simulating experiments combined with real scan traffic show that our method can detect uniform scan worms at early stage. In addition, because our method is based on the idea of trend detection, not traditionally burst detection, generic hacker attacks and scans cannot cause false alarms for their stochastic essence.