Worm detection and signature extraction based on communication characteristics

Worm detection and signature extraction was presented based on analysis of similar communication character-istics,which identifies the distinct communication pattern of worm spread,and evaluates the similarity metric of commu-nication characteristic sets,and detects worms by detecting their infectiv...

Full description

Saved in:
Bibliographic Details
Main Authors: XIN Yi1, FANG Bin-xing1, HE Long-tao2, YUN Xiao-chun2, LI Zhi-dong1
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2007-01-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/74655285/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1841537445189910528
author XIN Yi1
FANG Bin-xing1
HE Long-tao2
YUN Xiao-chun2
LI Zhi-dong1
author_facet XIN Yi1
FANG Bin-xing1
HE Long-tao2
YUN Xiao-chun2
LI Zhi-dong1
author_sort XIN Yi1
collection DOAJ
description Worm detection and signature extraction was presented based on analysis of similar communication character-istics,which identifies the distinct communication pattern of worm spread,and evaluates the similarity metric of commu-nication characteristic sets,and detects worms by detecting their infectivity with higher detection precision,generality and adaptability.Based on this,a heuristic detection framework is designed,which eliminates non-worm traffic from protocol,sequence,and content in three levels via blind,intent and lock track,then filters out worm packets and extracts signatures.The technique reduces data collection volume and analysis cost dramatically,and can detection worm and ex-tract signature quickly in the environment with high strength background noise.
format Article
id doaj-art-49c7c80321504475ae7c673a18fde9ab
institution Kabale University
issn 1000-436X
language zho
publishDate 2007-01-01
publisher Editorial Department of Journal on Communications
record_format Article
series Tongxin xuebao
spelling doaj-art-49c7c80321504475ae7c673a18fde9ab2025-01-14T08:35:04ZzhoEditorial Department of Journal on CommunicationsTongxin xuebao1000-436X2007-01-011774655285Worm detection and signature extraction based on communication characteristicsXIN Yi1FANG Bin-xing1HE Long-tao2YUN Xiao-chun2LI Zhi-dong1Worm detection and signature extraction was presented based on analysis of similar communication character-istics,which identifies the distinct communication pattern of worm spread,and evaluates the similarity metric of commu-nication characteristic sets,and detects worms by detecting their infectivity with higher detection precision,generality and adaptability.Based on this,a heuristic detection framework is designed,which eliminates non-worm traffic from protocol,sequence,and content in three levels via blind,intent and lock track,then filters out worm packets and extracts signatures.The technique reduces data collection volume and analysis cost dramatically,and can detection worm and ex-tract signature quickly in the environment with high strength background noise.http://www.joconline.com.cn/zh/article/74655285/wormcommunication characteristicsdetectionsignature extraction
spellingShingle XIN Yi1
FANG Bin-xing1
HE Long-tao2
YUN Xiao-chun2
LI Zhi-dong1
Worm detection and signature extraction based on communication characteristics
Tongxin xuebao
worm
communication characteristics
detection
signature extraction
title Worm detection and signature extraction based on communication characteristics
title_full Worm detection and signature extraction based on communication characteristics
title_fullStr Worm detection and signature extraction based on communication characteristics
title_full_unstemmed Worm detection and signature extraction based on communication characteristics
title_short Worm detection and signature extraction based on communication characteristics
title_sort worm detection and signature extraction based on communication characteristics
topic worm
communication characteristics
detection
signature extraction
url http://www.joconline.com.cn/zh/article/74655285/
work_keys_str_mv AT xinyi1 wormdetectionandsignatureextractionbasedoncommunicationcharacteristics
AT fangbinxing1 wormdetectionandsignatureextractionbasedoncommunicationcharacteristics
AT helongtao2 wormdetectionandsignatureextractionbasedoncommunicationcharacteristics
AT yunxiaochun2 wormdetectionandsignatureextractionbasedoncommunicationcharacteristics
AT lizhidong1 wormdetectionandsignatureextractionbasedoncommunicationcharacteristics