DocumentCode :
491699
Title :
A case study of unknown attack detection against Zero-day worm in the honeynet environment
Author :
Kim, Ikkyun ; Kim, Daewon ; Kim, Byunggoo ; Choi, Yangseo ; Yoon, Seongyong ; Oh, Jintae ; Jang, Jongsoo
Author_Institution :
Inf. Security Res. Div., Electron. & Telecommun. Res. Inst., Daejeon
Volume :
03
fYear :
2009
fDate :
15-18 Feb. 2009
Firstpage :
1715
Lastpage :
1720
Abstract :
We have presented an early detection system, ZASMIN (Zero-day Attack Signature Management Infrastructure), for novel network attack protection. This system provides early detection function and validation of attack at the moment the attacks start to spread on the network. In order to detect unknown network attack, the ZASMIN system has adopted various of new technologies, which are composed of suspicious traffic monitoring, attack validation, polymorphic worm recognition, signature generation. Some of these functionalities are implemented with hardware-based accelerator to be able to deal with giga-bit speed traffic, therefore, it can be applicable to Internet backbone or the bottle-neck point of high-speed enterprise network without any loss of traffic. In order to check the feasibility of ZASMIN, we have installed it on real honeynet environment, then we have analyzed the result about detection of unknown attack.
Keywords :
Internet; computer networks; invasive software; Internet backbone; ZASMIN; attack validation; enterprise network; honeynet environment; network attack protection; polymorphic worm recognition; signature generation; suspicious traffic monitoring; unknown attack detection; zero-day attack signature management infrastructure; zero-day worm; Computer networks; Computer worms; Environmental management; IP networks; Information security; Intrusion detection; Monitoring; Protection; Spine; Telecommunication traffic; Cyber attack; Intrusion Detection; Signature; Zero-day Attack;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Communication Technology, 2009. ICACT 2009. 11th International Conference on
Conference_Location :
Phoenix Park
ISSN :
1738-9445
Print_ISBN :
978-89-5519-138-7
Electronic_ISBN :
1738-9445
Type :
conf
Filename :
4809404
Link To Document :
بازگشت