Combined Behavior- and Signature-Based Internet Worm Detection System

被引:0
|
作者
Altaher, Altyeb [1 ]
Ramadass, Sureswaran [1 ]
Meulenberg, Andrew [1 ]
Abdat, Mustafa [1 ]
Ali, Ammar [1 ]
机构
[1] Univ Sains Malaysia, Natl Adv Ctr IPv6, George Town 11800, Malaysia
关键词
Internet worm detection; behavior based worm detection; signature based worm detection; worm propagation model; worm payload;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The number of polymorphic and new worms on the Internet is increasing rapidly. Worm infections cause traffic overloads in office networks and congestion of Internet links by replicating itself and hurting the affected companies by causing data loss and damage. Traditional signature-based worm detection systems fail to detect polymorphic and new, previously unseen worms. In this paper, based on an analysis of network traffic behavior, we develop the Combined Worm Detection System (CWDS) by combining signature-based worm detection and behavior-based worm detection. The CWDS uses the signature-based worm detection to detect the known worms, while it uses the behavior-based worm detection to detect polymorphic and new worms. An experimental study on real time network traffic and standard worm data sets is performed to test the proposed CWDS system. The experimental results demonstrate that the proposed CWDS system can detect both known and unknown worms with high detection rate and accuracy.
引用
收藏
页码:4213 / 4222
页数:10
相关论文
共 50 条
  • [41] SUIS: An Online Graphical Signature-Based User Identification System
    Alam, Shahid
    2016 SIXTH INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION AND COMMUNICATION TECHNOLOGY AND ITS APPLICATIONS (DICTAP), 2016, : 85 - 89
  • [42] A signature-based algorithm for computing the nondegenerate locus of a polynomial system
    Eder, Christian
    Lairez, Pierre
    Mohr, Rafael
    El Din, Mohab Safey
    JOURNAL OF SYMBOLIC COMPUTATION, 2023, 119 : 1 - 21
  • [43] SUIS: An online graphical Signature-Based User Identification System
    Department of Computer Science and Engineering, Qatar University, Doha, Qatar
    Int. Conf. Digit. Inf. Commun. Technol. Appl., DICTAP, 1600, (85-89):
  • [44] Improvement of an Incremental Signature-Based Comprehensive Grobner System Algorithm
    Dehghani Darmian, Mahdi
    MATHEMATICS IN COMPUTER SCIENCE, 2024, 18 (02)
  • [45] An Assessment Report on: Statistics-Based and Signature-Based Intrusion Detection Techniques
    Mehrotra, Latika
    Saxena, Prashant Sahai
    INFORMATION AND COMMUNICATION TECHNOLOGY (ICICT 2016), 2018, 625 : 321 - 327
  • [46] Grid-based internet worm behavior simulator
    刘扬
    王佰玲
    董开坤
    苑新玲
    张慈
    饶明
    Journal of Harbin Institute of Technology(New series), 2011, (03) : 41 - 47
  • [47] Grid-based internet worm behavior simulator
    刘扬
    王佰玲
    董开坤
    苑新玲
    张慈
    饶明
    Journal of Harbin Institute of Technology, 2011, 18 (03) : 41 - 47
  • [48] Robust Signature-Based Hyperspectral Target Detection Using Dual Networks
    Gao, Yanlong
    Feng, Yan
    Yu, Xumin
    Mei, Shaohui
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2023, 20
  • [49] Real-Time Signature-Based Detection Approach for SMS Botnet
    Alzahrani, Abdullah J.
    Ghorbani, Ali A.
    2015 THIRTEENTH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2015, : 157 - 164
  • [50] Next generation signature-based hyperspectral detection: A challenge to atmospheric modelers
    Schaum, A.
    Daniel, Brian
    ACTIVE AND PASSIVE SIGNATURES II, 2011, 8040