期刊文献+

基于近邻关系特征的多态蠕虫防御方法 被引量:4

Novel approach based on neighborhood relation signature against polymorphic internet worms
下载PDF
导出
摘要 结合多态蠕虫的特点,着重考虑负载字节之间的关系,将蠕虫负载内部的近邻关系特征(NRS,neighbor-hood-relation signature)提取出来用于蠕虫检测。NRS建立在蠕虫负载内部相邻字节之间关系的基础上,体现了某些多态蠕虫各形态之间的共性特征,能够更灵活地对多态蠕虫进行检测。设计了NRSGA(NRS generating algorithm)算法来提取1-NRS、2-NRS和(1,2)-NRS,并分别进行了实验,以测试特征提取过程的正确性和NRS检测蠕虫的有效性。实验结果表明,与其他方法相比,NRS在检测多态蠕虫时具有更低的漏报率,能够更好地防御多态蠕虫的传播。 A class of neighborhood-relation signatures(NRS) was proposed based on neighborhood relationship between worm bytes.Because NRS embodies common characteristics of different morph of some polymorphic worms,Different patterns of polymorphic worms efficiently were detected.NRS generating algorithm(NRSGA) was designed to generate three types of signatures: 1-NRS,2-NRS and(1,2)-NRS.Some experiments were performed to demonstrate the correct-ness of the process of signatures generation and the effectiveness of NRS.Experiment results show that our approach has lower false negative ratio in detecting worms,and is effective to prevent polymorphic worms from propagating.
出处 《通信学报》 EI CSCD 北大核心 2011年第8期150-158,共9页 Journal on Communications
基金 国家重点基础研究发展计划("973"计划)基金资助项目(2008CB317107) 国家教育部创新团队资助项目(IRT0661)~~
关键词 信息安全 蠕虫特征 近邻关系特征 多态蠕虫 蠕虫检测 information security worm signature NRS polymorphic worm worm detection
  • 相关文献

参考文献21

二级参考文献102

共引文献272

同被引文献57

  • 1杨峰,段海新,李星.网络蠕虫扩散中蠕虫和良性蠕虫交互过程建模与分析[J].中国科学(E辑),2004,34(8):841-856. 被引量:27
  • 2文伟平,卿斯汉,蒋建春,王业君.网络蠕虫研究与进展[J].软件学报,2004,15(8):1208-1219. 被引量:187
  • 3王平,方滨兴,云晓春.基于自动特征提取的大规模网络蠕虫检测[J].通信学报,2006,27(6):87-93. 被引量:9
  • 4COMAR P M,LIU L,SAHA S,et al.Combining supervised and unsupervised learning for zero-day malware detection[A].Proceedings of 32nd Annual IEEE International Conference on Computer Communications (INFOCOM 2013)[C].Turin,Italy,2013.2022-2030.
  • 5KAUR R.,SINGH M.Efficient hybrid technique for detecting zero-day polymorphic worms[A].2014 IEEE International Advance Computing Conference (IACC)[C].Gurgaon,India,2014.95-100.
  • 6KAUR R,SINGH M.A survey on zero-day polymorphic worm detection techniques[J].IEEE Communications Surveys & Tutorials,2014:1-30.
  • 7PORTOKALIDIS G,BOSH.Sweetbait:zero-hour worm detection and containment using low-and high-interaction honeypots[J].Computer Networks,2007,51(5):1256-1274.
  • 8CAI M,HWANG K,PAN J,et al.Wormshield:fast worm signature generation with distributed fingerprint aggregation[J].IEEE Transactions on Dependable and Secure Computing,2007,4(2):88-104.
  • 9RANJAN S,SHAH S,NUCCI A,et al.Dowitcher:effective worm detection and containment in the internet core[A].IEEE INFOCOM 2007[C].Alaska,USA,2007.2541-2545.
  • 10MOHAMMED MMZE,CHAN H A,VENTURA N,et al.An automated signature generation method for zero-day polymorphic worms based on multilayer perceptron model[A].2013 International Conference on Advanced Computer Science Applications and Technologies (ACSAT)[C].Zhengzhou,China,2013.450-455.

引证文献4

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部