Graph based signature classes for detecting polymorphic worms via content analysis

被引:9
作者
Bayoglu, Burak [1 ,2 ]
Sogukpinar, Ibrahim [2 ]
机构
[1] Natl Res Inst Elect & Cryptol, TR-41470 Gebze, Turkey
[2] Gebze Inst Technol, TR-41400 Gebze, Turkey
关键词
Polymorphic worm; Worm detection; Graph based signature;
D O I
10.1016/j.comnet.2011.11.007
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Malicious softwares such as trojans, viruses, or worms can cause serious damage for information systems by exploiting operating system and application software vulnerabilities. Worms constitute a significant proportion of overall malicious software and infect a large number of systems in very short periods. Polymorphic worms combine polymorphism techniques with self-replicating and fast-spreading characteristics of worms. Each copy of a polymorphic worm has a different pattern so it is not effective to use simple signature matching techniques. In this work, we propose a graph based classification framework of content based polymorphic worm signatures. This framework aims to guide researchers to propose new polymorphic worm signature schemes. We also propose a new polymorphic worm signature scheme, Conjunction of Combinational Motifs (CCM), based on the defined framework. CCM utilizes common substrings of polymorphic worm copies and also the relation between those substrings through dependency analysis. CCM is resilient to new versions of a polymorphic worm. CCM also automatically generates signatures for new versions of a polymorphic worm, triggered by partial signature matches. Experimental results support that CCM has good flow evaluation time performance with low false positives and low false negatives. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:832 / 844
页数:13
相关论文
共 29 条
[1]  
[Anonymous], 2007, CLET POLYMORPHIC ENG
[2]  
[Anonymous], 2008, APACHE APR PSPRINTF
[3]  
[Anonymous], 2007, ADMMUTATE POLYMORPHI
[4]  
[Anonymous], P IEEE S SEC PRIV
[5]  
[Anonymous], 2011, ATPHTTPD REMOTELY EX
[6]  
[Anonymous], 2008, MULTIPLE BUFFER OVER
[7]  
[Anonymous], 2008, CERT ADV CA 2001 02
[8]  
Bayoglu B., 2008, INT C PERV SERV 4 IN, P7
[9]   Polymorphic worm detection using strong token-pair signatures [J].
Bayoglu, Burak ;
Sogukpinar, Ibrahim .
TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2009, 17 (02) :163-182
[10]  
Cavallaro L., 2008, Proceedings of the fourth international workshop of Software engineering for secure systems, New York, P41