• DocumentCode
    3667232
  • Title

    Automatic signature generation for polymorphic worms by combination of token extraction and sequence alignment approaches

  • Author

    Razieh Eskandari;Mehdi Shajari;Asadallah Asadi

  • Author_Institution
    Department of Engineering, Shahrekord University, Iran
  • fYear
    2015
  • fDate
    5/1/2015 12:00:00 AM
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    As modern worms spread quickly; any countermeasure based on human reaction is barely fast enough to thwart the threat. Moreover, because polymorphic worms could generate mutated instances, they are more complex than non-mutating ones. Currently, the content-based signature generation of polymorphic worms is a challenge for network security. Several signature classes have been proposed for polymorphic worms. Although previously proposed schemes consider patterns such as 1-byte invariants and distance restrictions, they could not handle neither large payloads nor the big size pool of worm instances. Moreover, they are prone to noise injection attack. We proposed a method to combine two approaches of creating a polymorphic worm signature in a new way that avoid the limitation of both approaches. The proposedsignature generation scheme is based on token extraction and multiple sequence alignment, widely used in Bioinformatics. This approach provides speed, accuracy, and flexibility in terms of noise tolerance. The evaluations demonstrate these claims.
  • Keywords
    "Grippers","Bioinformatics","Protocols","Monitoring","Biomedical monitoring","Intrusion detection","Computers"
  • Publisher
    ieee
  • Conference_Titel
    Information and Knowledge Technology (IKT), 2015 7th Conference on
  • Print_ISBN
    978-1-4673-7483-5
  • Type

    conf

  • DOI
    10.1109/IKT.2015.7288733
  • Filename
    7288733