NoBot: Embedded Malware Detection for Endpoint Devices

被引:3
作者
Menten, Lawrence E.
Chen, Aiyou
Stiliadis, Dimitrios [1 ,2 ]
机构
[1] Alcatel Lucent Bell Labs, Murray Hill, NJ USA
[2] Alcatel Lucent Venture, Murray Hill, NJ USA
关键词
D O I
10.1002/bltj.20492
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
NoBot is a novel malware detection system that employs packet classification and distinct counting techniques to achieve reliable detection and identification of malware by observing the traffic to and from a network-connected host. The solution is designed to be economically incorporated into endpoint devices, such as Ethernet switches, Gigabit passive optical network (GPON) devices, and digital subscriber line access multiplexers (DSLAMs) leveraging the integral features of the hosting device, such as packet classification, packet counting, packet-forwarding features, and the computing resources of the control processor. NoBot combines these features with deep packet inspection and distinct counting to detect the presence of malware with a low rate of false positive detections. The NoBot software has been incorporated into a Linux device driver, installed into an Android-based smart phone, and implemented as a preprocessor module for the open source Snort Intrusion detection and prevention System (IDS/IPS). (C) 2011 Alcatel-Lucent
引用
收藏
页码:155 / 170
页数:16
相关论文
共 20 条
[1]  
[Anonymous], KNOW YOUR EN FAST FL
[2]  
Chen AY, 2009, PROC INT CONF DATA, P1171, DOI 10.1109/ICDE.2009.193
[3]  
Davis CR, 2008, LECT NOTES COMPUT SC, V5283, P461
[4]  
Estan C., 2003, P 3 ACM SIGCOMM C IN, P153, DOI DOI 10.1145/948205.948225
[5]  
Forrest S., 2008, Proceedings of the Workshop on New Security Paradigms NSPW, P99
[6]  
FRATTO M, 2008, INFORM WEEK 0809
[7]  
GONSALVES A, 2010, INFORM WEEK 0422
[8]  
Gu G. F., 2007, P 16 USENIX SEC S, P167
[9]  
Holz T., 2008, P 16 ANN NETW DISTR
[10]  
JOHN JP, 2009, P 6 USENIX S NETW SY, P291