首页> 外文期刊>Computers & Security >Using a bioinformatics approach to generate accurate exploit-based signatures for polymorphic worms
【24h】

Using a bioinformatics approach to generate accurate exploit-based signatures for polymorphic worms

机译:使用生物信息学方法为多态蠕虫生成基于攻击的准确签名

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we propose Simplified Regular Expression (SRE) signature, which uses multiple sequence alignment techniques, drawn from bioinformatics, in a novel approach to generating more accurate exploit-based signatures. We also provide formal definitions of what is "a more specific" and what is "the most specific" signature for a polymorphic worm and show that the most specific exploit-based signature generation is NP-hard. The approach involves three steps: multiple sequence alignment to reward consecutive substring extractions, noise elimination to remove noise effects, and signature transformation to make the SRE signature compatible with current IDSs. Experiments on a range of polymorphic worms and real-world polymorphic shellcodes show that our bioinformatics approach is noise-tolerant and as that because it extracts more polymorphic worm characters, like one-byte invariants and distance restrictions between invariant bytes, the signatures it generates are more accurate and precise than those generated by some other exploit-based signature generation schemes.
机译:在本文中,我们提出了一种简化的正则表达式(SRE)签名,该签名使用了一种从生物信息学中提取的多种序列比对技术,以一种新颖的方式来生成更准确的基于漏洞利用的签名。我们还为多态蠕虫提供了“更具体的”签名和“最具体的”签名的正式定义,并表明最具体的基于漏洞利用的签名生成是NP-hard。该方法涉及三个步骤:多重序列比对,以奖励连续的子串提取;噪声消除,以消除噪声影响;以及签名转换,以使SRE签名与当前IDS兼容。在一系列多态蠕虫和现实世界中的多态shellcode上进行的实验表明,我们的生物信息学方法具有耐噪性,并且由于它提取了更多的多态蠕虫字符,例如一字节不变式和不变字节之间的距离限制,因此生成的签名是比其他一些基于漏洞利用的签名生成方案生成的签名更准确,更精确。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号