首页    期刊浏览 2024年11月08日 星期五
登录注册

文章基本信息

  • 标题:Generating Rule-Based Signatures for Detecting Polymorphic Variants Using Data Mining and Sequence Alignment Approaches
  • 作者:Vijay Naidu ; Jacqueline Whalley ; Ajit Narayanan
  • 期刊名称:Journal of Information Security
  • 印刷版ISSN:2153-1234
  • 电子版ISSN:2153-1242
  • 出版年度:2018
  • 卷号:09
  • 期号:04
  • 页码:265-298
  • DOI:10.4236/jis.2018.94019
  • 语种:English
  • 出版社:Scientific Research Publishing
  • 摘要:Antiviral software systems (AVSs) have problems in detecting polymorphic variants of viruses without specific signatures for such variants. Previous alignment-based approaches for automatic signature extraction have shown how signatures can be generated from consensuses found in polymorphic variant code. Such sequence alignment approaches required variable length viral code to be extended through gap insertions into much longer equal length code for signature extraction through data mining of consensuses. Non-nested generalized exemplars (NNge) are used in this paper in an attempt to further improve the automatic detection of polymorphic variants. The important contribution of this paper is to compare a variable length data mining technique using viral source code to the previously used equal length data mining technique obtained through sequence alignment. This comparison was achieved by conducting three different experiments (i.e. Experiments I-III). Although Experiments I and II generated unique and effective syntactic signatures, Experiment III generated the most effective signatures with an average detection rate of over 93%. The implications are that future, syntactic-based smart AVSs may be able to generate effective signatures automatically from malware code by adopting data mining and alignment techniques to cover for both known and unknown polymorphic variants and without the need for semantic (run-time) analysis.
  • 关键词:NNge Classifier;Gap Penalties;JS.Cassandra Virus;Polymorphic Virus;Automatic Signature Generation;Sequence Alignment;Syntactic Exploration
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有