DocumentCode :
3667232
Title :
Automatic signature generation for polymorphic worms by combination of token extraction and sequence alignment approaches
Author :
Razieh Eskandari;Mehdi Shajari;Asadallah Asadi
Author_Institution :
Department of Engineering, Shahrekord University, Iran
fYear :
2015
fDate :
5/1/2015 12:00:00 AM
Firstpage :
1
Lastpage :
6
Abstract :
As modern worms spread quickly; any countermeasure based on human reaction is barely fast enough to thwart the threat. Moreover, because polymorphic worms could generate mutated instances, they are more complex than non-mutating ones. Currently, the content-based signature generation of polymorphic worms is a challenge for network security. Several signature classes have been proposed for polymorphic worms. Although previously proposed schemes consider patterns such as 1-byte invariants and distance restrictions, they could not handle neither large payloads nor the big size pool of worm instances. Moreover, they are prone to noise injection attack. We proposed a method to combine two approaches of creating a polymorphic worm signature in a new way that avoid the limitation of both approaches. The proposedsignature generation scheme is based on token extraction and multiple sequence alignment, widely used in Bioinformatics. This approach provides speed, accuracy, and flexibility in terms of noise tolerance. The evaluations demonstrate these claims.
Keywords :
"Grippers","Bioinformatics","Protocols","Monitoring","Biomedical monitoring","Intrusion detection","Computers"
Publisher :
ieee
Conference_Titel :
Information and Knowledge Technology (IKT), 2015 7th Conference on
Print_ISBN :
978-1-4673-7483-5
Type :
conf
DOI :
10.1109/IKT.2015.7288733
Filename :
7288733
Link To Document :
بازگشت