首页> 外文会议>International Conference on Security and Management >Zero-day Polymorphic Worms Detection Using A modified Boyer-Moore Algorithm
【24h】

Zero-day Polymorphic Worms Detection Using A modified Boyer-Moore Algorithm

机译:使用修改的博米摩尔算法检测零多态性蠕虫蠕虫

获取原文

摘要

Internet worms cause a great damage to network and information infrastructure. Therefore, the networks must be protected against Internet worms and other attacks. In this paper we propose automatic system for signature generation for Zero-day polymorphic worms. We have designed a novel double-honeynet system, which is able to detect new worms that have not been seen before. The system is based on a Boyer-Moore Algorithm that uses polymorphic worm substrings to find multiple invariant substrings that are shared between all polymorphic worm instances and use them as signatures. The system is able to generate accurate signatures for single and multiple worms.
机译:互联网蠕虫对网络和信息基础设施造成巨大损害。因此,必须保护网络免受互联网蠕虫和其他攻击。在本文中,我们提出了零日多态性蠕虫的签名生成自动系统。我们设计了一种新型双人性网络系统,能够检测以前没有看到的新蠕虫。该系统基于博伊尔摩尔算法,该算法使用多态蠕虫子字符串来找到在所有多态蠕虫实例之间共享的多个不变子程,并将其用作签名。该系统能够为单个和多个蠕虫产生准确的签名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号