Behaviour Based Worm Detection and Signature Automation
2011
Problem statement: A worm is a malicious piece of code that self-prop agates, often via network connections, to exploit security flaws in c omputers connected through the network. In general, worms do not need any human intervention to propagate and are considered a real threat to network assets and the properties of organizations. An Intr usion Detection Systems (IDSs) are employed to detect the presence of the worms in the network. Approach: This study proposed a new behaviour- based worm detection and signature automation approach that consists of scanning characteristics to find vulnerable hosts and indicate the correlation between an infected host and potential destination hosts. Results: This approach can be distinguish between network s canning (random and sequential TCP and UDP worm scanning) triggered by infected and non-infected hosts. In addition, the ability to detect the worms based on its behaviours. Conclusion: Identifying network worms at an early stage can increase the protection of network services and vulnerable hosts.
- Correction
- Source
- Cite
- Save
- Machine Reading By IdeaReader
9
References
3
Citations
NaN
KQI