Efficient content-based detection of zero-day worms

Efficient content-based detection of zero-day worms
复制标题

基于内容的零日蠕虫的高效检测

DOI:
10.1109/icc.2005.1494469
复制
发表时间:
2005
期刊:
IEEE International Conference on Communications, 2005. ICC 2005. 2005
影响因子:
--
通讯作者:
E. Markatos
E. Markatos
中科院分区:
--
文献类型:
--
作者:
P. Akritidis;K. Anagnostakis;E. Markatos

文献摘要

被引文献

相似文献

最近的网络安全事件表明,互联网蠕虫可以传播得如此之快,以至于不可能及时做出人为的反应,因此对网络攻击的初步反应必须自动化。对抗新的未知蠕虫的第一步是能够在它们传播的最初阶段检测和识别它们。在本文中,我们提出了一种基于识别指向多个目标主机的相似数据包内容来检测新蠕虫的新方法。我们使用包含真实蠕虫的真实流量痕迹来评估我们的方法。我们的结果表明,我们的方法能够识别新的蠕虫,同时产生的假警报达到低至零。
Recent cybersecurity incidents suggest that Internet worms can spread so fast that in-time human-mediated reaction is not possible, and therefore initial response to cyberattacks has to be automated. The first step towards combating new unknown worms is to be able to detect and identify them at the first stages of their spread. In this paper, we present a novel method for detecting new worms based on identifying similar packet contents directed to multiple destination hosts. We evaluate our method using real traffic traces that contain real worms. Our results suggest that our approach is able to identify novel worms while at the same time the generated false alarms reach as low as zero percent.