Behaviour Based Worm Detection and Signature Automation

2011 
Problem statement: A worm is a malicious piece of code that self-prop agates, often via network connections, to exploit security flaws in c omputers connected through the network. In general, worms do not need any human intervention to propagate and are considered a real threat to network assets and the properties of organizations. An Intr usion Detection Systems (IDSs) are employed to detect the presence of the worms in the network. Approach: This study proposed a new behaviour- based worm detection and signature automation approach that consists of scanning characteristics to find vulnerable hosts and indicate the correlation between an infected host and potential destination hosts. Results: This approach can be distinguish between network s canning (random and sequential TCP and UDP worm scanning) triggered by infected and non-infected hosts. In addition, the ability to detect the worms based on its behaviours. Conclusion: Identifying network worms at an early stage can increase the protection of network services and vulnerable hosts.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    9
    References
    3
    Citations
    NaN
    KQI
    []