首页> 外文期刊>Turkish Journal of Electrical Engineering and Computer Sciences >Polymorphic worm detection using strong token-pair signatures
【24h】

Polymorphic worm detection using strong token-pair signatures

机译:使用强大的令牌对签名进行多态蠕虫检测

获取原文
获取外文期刊封面目录资料

摘要

Malicious software has become a big threat to informationsystems, which are widely used to store, transfer and processinformation for many critical assets. Worms are one of the mostharmful network-enabled malicious software that can threaten networksand applications. Two main characteristics of worms distinguish themfrom the well-known virus programs and as a result are much moredangerous than the virus programs. First, they do not need to attachthemselves to an existing program. Second, worms do not requireend-user interaction to realize the intended attack. Therefore, alarge number of victims can be infected in a short time. Polymorphicworms are a special subset of worm family which are more difficult todetect. Polymorphism is the key that facilitates creating differentlooking polymorphic worm copies while keeping the original worm codeintact. Each variant for a polymorphic worm has a different patternthat it is not effective to use simple signature matching techniques.In this work, Strong Token-Pair(STP) signature scheme has beenproposed to detect polymorphic worms. Experimental results supportthat STP signatures can be used with low false negative and falsepositive rates.
机译:恶意软件已经成为对信息系统的巨大威胁,信息系统被广泛用于存储,传输和处理许多关键资产的信息。蠕虫是可危害网络和应用程序的最具危害性的基于网络的恶意软件之一。蠕虫的两个主要特征将其与著名的病毒程序区分开来,因此比病毒程序危险得多。首先,他们不需要将自己附加到现有程序上。其次,蠕虫不需要最终用户交互即可实现预期的攻击。因此,大量受害者可以在短时间内被感染。多态蠕虫是蠕虫家族的一个特殊子集,较难检测。多态性是在保持原始蠕虫代码完整的同时,有助于创建外观不同的多态蠕虫副本的关键。多态蠕虫的每个变体都有不同的模式,使用简单的签名匹配技术并不有效。在这项工作中,提出了强令牌对(STP)签名方案来检测多态蠕虫。实验结果支持STP签名可以以较低的假阴性和假阳性率使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号