Automated signature generation for polymorphic worms using Substrings extraction and Principal Component Analysis

被引:0
作者
Mondal, Avijit [1 ]
Paul, Subrata [2 ]
Mitra, Anirban [2 ]
Gope, Biswajit [3 ]
机构
[1] BCET, Dept IT, Durgapur, W Bengal, India
[2] VITAM, Dept CSE, Berhampur, Odisha, India
[3] BCET, Dept CSE, Durgapur, W Bengal, India
来源
2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (ICCIC) | 2015年
关键词
worms; Intrusion Detection System; Polymorphic Worms; Principal Comonent Analysis;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Internet Security system has been largely threatened due to increase in Internet Worms at an alarming rate. Intrusion Detection System signature has been manually generated by security experts during their study on the network status after the release of a new worm. But it can take place after a significant loss of assets. In this research work, we are proposing an automatic method which will generate signature for detection of polymorphic worms. We will be applying Principal Component Analysis (PCA) for determining the important substrings that appears mostly and are pooled amongst the instances of polymorphic worms for using them as signatures. The results generated show the successful detection of polymorphic worms using zero false positives and low false negatives by the PCA.
引用
收藏
页码:428 / 431
页数:4
相关论文
共 21 条
[1]  
AGGARWAL CC, 2001, P ACM SIGMOD C SANT
[2]   A Generalized Least-Square Matrix Decomposition [J].
Allen, Genevera I. ;
Grosenick, Logan ;
Taylor, Jonathan .
JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2014, 109 (505) :145-159
[3]  
[Anonymous], 2011, DE FACT STAND INTR D
[4]  
[Anonymous], 1997, ACM SIGACT NEWS
[5]  
Bidgoli H., 2006, HDB INFORM SECURITY
[6]  
Cavallaro L., 2008, P 4 INT WORKSH SOFTW, P41
[7]   Backwards Principal Component Analysis and Principal Nested Relations [J].
Damon, James ;
Marron, J. S. .
JOURNAL OF MATHEMATICAL IMAGING AND VISION, 2014, 50 (1-2) :107-114
[8]  
Kim H., 2013, IEEE T AUTOM SCI ENG, P1, DOI DOI 10.1109/ISR.2013.6695682
[9]  
KIM HA, 2004, P 13 USENIX SEC S SA
[10]  
KREIBICH C, 2003, WORKSH HOT TOP NETW