earticle

논문검색

PolyS: Network-based Signature Generation for Zero-day Polymorphic Worms

초록

영어

With growing sophistication of computer worms, it is very important to detect and prevent the worms quickly and accurately at their early phase of infection. Traditional signature based IDS, though effective for known attacks but failed to handle the zero-day attack promptly. Recent works on polymorphic worms does not guarantee accurate signature in presence of noise in suspicious flow samples. In this paper we propose PolyS, an improved version of Hamsa, a network based automated signature generation scheme to thwart zero-day polymorphic worms. We contribute a novel architecture that reduces the noise in suspicious traffic pool, thus enhancing the accuracy of worm’s signature. Also we propose a signature generation algorithm for successfully matching polymorphic worm payload with higher speed and memory efficiency. Analysis shows that our system is fast, accurate, attack-resilient and capable of generating quality signature with low false positive and false negative.

목차

Abstract
 1. Introduction
 2. Related Work
 3. Structure of Polymorphic worms
 4. System Model
  4.1. Architecture
  4.2. Data Control
  4.3 Data Capture
 5. Problem definition
 6. Signature Generation
 7. Conclusion
 Acknowledgements
 References

저자정보

  • Sounak Paul Dept. of Information Technology, Birla Institute of Technology
  • Bimal Kumar Mishra Dept. of Applied Mathematics, Birla Institute of Technology

참고문헌

자료제공 : 네이버학술정보

    ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

    0개의 논문이 장바구니에 담겼습니다.