Automated signature generation for polymorphic worms using substrings extraction and principal component analysis

Avijit Mondal, Subrata Paul, A. Mitra, Biswajit Gope
{"title":"Automated signature generation for polymorphic worms using substrings extraction and principal component analysis","authors":"Avijit Mondal, Subrata Paul, A. Mitra, Biswajit Gope","doi":"10.1109/ICCIC.2015.7435724","DOIUrl":null,"url":null,"abstract":"Internet Security system has been largely threatened due to increase in Internet Worms at an alarming rate. Intrusion Detection System signature has been manually generated by security experts during their study on the network status after the release of a new worm. But it can take place after a significant loss of assets. In this research work, we are proposing an automatic method which will generate signature for detection of polymorphic worms. We will be applying Principal Component Analysis (PCA) for determining the important substrings that appears mostly and are pooled amongst the instances of polymorphic worms for using them as signatures. The results generated show the successful detection of polymorphic worms using zero false positives and low false negatives by the PCA.","PeriodicalId":276894,"journal":{"name":"2015 IEEE International Conference on Computational Intelligence and Computing Research (ICCIC)","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE International Conference on Computational Intelligence and Computing Research (ICCIC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCIC.2015.7435724","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Internet Security system has been largely threatened due to increase in Internet Worms at an alarming rate. Intrusion Detection System signature has been manually generated by security experts during their study on the network status after the release of a new worm. But it can take place after a significant loss of assets. In this research work, we are proposing an automatic method which will generate signature for detection of polymorphic worms. We will be applying Principal Component Analysis (PCA) for determining the important substrings that appears mostly and are pooled amongst the instances of polymorphic worms for using them as signatures. The results generated show the successful detection of polymorphic worms using zero false positives and low false negatives by the PCA.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于子串提取和主成分分析的多态蠕虫自动签名生成
由于网络蠕虫病毒以惊人的速度增加,网络安全系统受到了很大的威胁。入侵检测系统签名是安全专家在研究新蠕虫病毒发布后的网络状态时手工生成的。但这也可能发生在重大资产损失之后。在这项研究中,我们提出了一种自动生成签名的方法来检测多态蠕虫。我们将应用主成分分析(PCA)来确定最重要的子字符串,这些子字符串在多态蠕虫的实例中最多出现,并汇集在一起,以便将它们用作签名。生成的结果表明,通过PCA成功地检测出了零假阳性和低假阴性的多态蠕虫。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Multi agent based audio steganography Non-invasive tracking and monitoring glucose content using near infrared spectroscopy Deterministic approach for bridging fault detection in Peres-Fredkin and Toffoli based reversible circuits Field oriented control of Doubly Fed Induction Generator in wind power system Evaluation of PSE, STFT and probability coefficients for classifying two directions from EEG using radial basis function
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1