• DocumentCode
    2311718
  • Title

    Detection of Worm Propagation Engines in the System Call Domain using Colored Petri Nets

  • Author

    Tokhtabayev, Arnur G. ; Skormin, Victor A. ; Dolgikh, Andrey M.

  • Author_Institution
    Center for Adv. Inf. Technol., Binghamton Univ., Binghamton, NY
  • fYear
    2008
  • fDate
    7-9 Dec. 2008
  • Firstpage
    59
  • Lastpage
    68
  • Abstract
    While network worms carry various payloads and may utilize any available exploits, they all have one common component - the propagation engine. Moreover, it is important to note that the number of conceptually distinct propagation engines employed by existing network worms is quite limited. This paper presents a novel signature-based approach for detecting attacks perpetrated by network worms as a manifestation of a semantic functionality performed by one of the few known propagation engines. We propose a novel methodology to recognize any semantic functionality in the system call domain through utilizing colored Petri Nets. In this application, Petri Nets embody behavior-based signatures of the propagation engine functionalities. These signatures are indicative of the shell code activity in the first stage of the worm proliferation. We developed, tested and evaluated a propagation engine detector (PED) system that detects activity of the worm shell code executed by a process during an attack. Moreover, PED is able to recognize the type of propagation engine employed by the attacking worm.
  • Keywords
    Petri nets; digital signatures; graph colouring; invasive software; behavior-based signatures; colored Petri nets; network worms; propagation engine detector system; signature-based approach; system call domain; worm proliferation; worm propagation engines; worm shell code; Capacitive sensors; Code standards; Detectors; Engines; Functional programming; Image databases; Information technology; Payloads; Petri nets; System testing; Colored Petri Nets; IDS; Propagation engine; System calls;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
  • Conference_Location
    Austin, Texas
  • ISSN
    1097-2641
  • Print_ISBN
    978-1-4244-3368-1
  • Electronic_ISBN
    1097-2641
  • Type

    conf

  • DOI
    10.1109/PCCC.2008.4745108
  • Filename
    4745108