首页> 外文期刊>Computers, IEEE Transactions on >Signature Tree Generation for Polymorphic Worms
【24h】

Signature Tree Generation for Polymorphic Worms

机译:多态蠕虫的签名树生成

获取原文
获取原文并翻译 | 示例

摘要

Network-based signature generation (NSG) has been proposed as a way to automatically and quickly generate accurate signatures for worms, especially polymorphic worms. In this paper, we propose a new NSG systemȁ4;PolyTree, to defend against polymorphic worms. We observe that signatures from worms and their variants are relevant and a tree structure can properly reflect their familial resemblance. Hence, in contrast to an isolated view of generated signatures in previous approaches, PolyTree organizes signatures extracted from worm samples into a tree structure, called signature tree, based on the formally defined "more specificȁD; relation of simplified regular expression signatures. PolyTree is composed of two components, signature tree generator and signature selector. The signature tree generator implements an incremental signature tree generation algorithm from worm sample clustering, up-to-date signature refinement to efficient tree construction. The incremental signature tree construction gives insight on how the worm variants evolve over time and allows signature refinement upon a new worm sample arrival. The signature selector chooses a set of signatures for worm detection from a benign traffic pool and the current signature tree constructed by the signature tree generator. Experiments show that PolyTree cannot only generate accurate signatures for polymorphic worms with noise, but these signatures are well organized in the signature tree to reflect the inherent relations of worms and their variants.
机译:已经提出了基于网络的签名生成(NSG)作为自动,快速地为蠕虫(尤其是多态蠕虫)生成准确签名的方法。在本文中,我们提出了一种新的NSG系统ȁ4; PolyTree,以防御多态蠕虫。我们观察到蠕虫及其变种的特征是相关的,并且树形结构可以正确反映它们的家族相似性。因此,与以前的方法中生成的签名的隔离视图相反,PolyTree根据正式定义的“更具体的D;简化的正则表达式签名的关系”,将从蠕虫样本中提取的签名组织成树结构,称为签名树。由签名树生成器和签名选择器这两个组件组成,签名树生成器实现了从蠕虫样本聚类,最新签名细化到高效树构建的增量签名树生成算法。变种会随着时间的推移而发展,并允许在新蠕虫样本到达时对特征进行细化,特征选择器从良性流量池和由特征树生成器构建的当前特征树中选择一组特征进行蠕虫检测,实验表明PolyTree不能仅生成多态蠕虫机智的准确特征噪声,但是这些签名在签名树中井井有条,以反映蠕虫及其变种的固有关系。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号