DocumentCode :
2034241
Title :
A novel approach to worm detection systems
Author :
Al-Saawy, Yazed B. ; Cau, Antonio ; Siewe, Francois
Author_Institution :
Software Technol. Res. Lab., De Montfort Univ., Leicester, UK
fYear :
2015
fDate :
28-30 July 2015
Firstpage :
1201
Lastpage :
1205
Abstract :
Computer worms are a type of malicious malware that prey on networked machines. A number of different detection mechanisms have been presented in the literature to detect worms. However, a common drawback of these mechanisms is that any failure to detect the worms results in damaging the real machines. This study proposes a new approach to detection that goes beyond the currently available signature and behavior-based approaches. In contrast to the traditional worm detection system (WDS) that use signature and behavior-based approaches, our proposed approach is based on detection by the damage caused by worms on dummy machines rather than the real machines. The proposed WDS adds additional security as compared to the currently used systems by allowing worms to conduct their normal behavior in a dummy host, thus protecting the rest of the network from damage. The proposed WDS was designed within a network setting and was capable of sending and receiving files and messages between hosts as part of the overall detection mechanism.
Keywords :
digital signatures; invasive software; WDS; behavior-based approach; malware; signature-based approach; worm detection system; Databases; Grippers; Internet; Intrusion detection; Malware; Software; Worms detection; behaviour-based; computer security; damage; dummy host; signature-based;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Science and Information Conference (SAI), 2015
Conference_Location :
London
Type :
conf
DOI :
10.1109/SAI.2015.7237297
Filename :
7237297
Link To Document :
بازگشت