首页    期刊浏览 2024年11月24日 星期日
登录注册

文章基本信息

  • 标题:Honeypot-based Signature Generation for Polymorphic Worms
  • 本地全文:下载
  • 作者:Sounak Paul ; Bimal Kumar Mishra
  • 期刊名称:International Journal of Security and Its Applications
  • 印刷版ISSN:1738-9976
  • 出版年度:2014
  • 卷号:8
  • 期号:6
  • 页码:101-114
  • DOI:10.14257/ijsia.2014.8.6.10
  • 出版社:SERSC
  • 摘要:With the growing sophistication of computer worms, information security has become a prime concern for individuals, community and organizations. Traditional signature based IDS, though effective for known attacks but failed to handle the unknown attack promptly. This paper describes a novel honeypot system which isolates the suspicious traffic from normal traffic, and capture most useful information regarding the worm's activities, without attacker's knowledge. Our system will be used for critical study of structure and behavior of most sophisticated worms and then forwards the necessary input to Signature Generation Module for automatically generating signature of unknown polymorphic worms. Our attempt is to analyze the invariant content of polymorphic worms and using a probabilistic approach we compute the signature of worm with low false positive. Evaluation based on synthetically generated polymorphic worms demonstrate that our system is able to enhance the capability of IDS signature library and increases the probability of detecting polymorphic worms with efficiency, accuracy.
  • 关键词:polymorphic worm; signature; honeypot; probability; false positive; token; ; intrusion detection
国家哲学社会科学文献中心版权所有