• DocumentCode
    1605418
  • Title

    xMiner: Nip the Zero Day Exploits in the Bud

  • Author

    Rafique, M. Zubair ; Abulaish, Muhammad

  • Author_Institution
    Center of Excellence in Inf. Assurance (CoEIA), King Sand Univ., Riyadh, Saudi Arabia
  • fYear
    2011
  • Firstpage
    99
  • Lastpage
    106
  • Abstract
    Vulnerability exploits present in malformed messages are one of the major sources to remotely launch malicious activities in different protocols. Sometimes, a single malformed message could be enough to crash remote servers or to gain unfettered access over them. In this paper, we propose the design of a generic vulnerability exploits detection system xMiner to detect malformed messages in real time for avoiding any network hazard. The proposed xMiner exploits the information embedded within byte-level sequences of network messages. xMiner applies multi-order Markov process and principal component analysis (PCA) to extract novel discriminative features and uses them to detect attacks launched through malicious packets in real-time. The novelty of xMiner lies in its light-weight design which requires less processing and memory resources and makes it easily deployable on resource-constrained devices like smart phones. The system is evaluated on real-world datasets pertaining to three different protocols - HTTP, FTP and SIP. Five different classifiers are deployed to establish the effectiveness of the proposed system. On evaluation we found that the decision tree classifier performs well for HTTP and FTP datasets whereas, SVM shows highest performance in case of SIP packets.
  • Keywords
    Markov processes; computer network security; invasive software; principal component analysis; Markov process; byte-level sequences; discriminative features; malformed messages; malicious activities; malicious packets; network hazard; network messages; principal component analysis; resource-constrained devices; smart phones; vulnerability exploits detection system; xMiner; Correlation; Feature extraction; Markov processes; Principal component analysis; Protocols; Real time systems; Servers; Network security; feature extraction; machine learning; vulnerability exploits detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Computing and Applications (NCA), 2011 10th IEEE International Symposium on
  • Conference_Location
    Cambridge, MA
  • Print_ISBN
    978-1-4577-1052-0
  • Electronic_ISBN
    978-0-7695-4489-2
  • Type

    conf

  • DOI
    10.1109/NCA.2011.21
  • Filename
    6038590