Polymorphic Worm Detection Using Signatures Based on Neighborhood Relation Conference Paper uri icon

abstract

  • In recent years, worm signatures suffer from difficulties to detect polymorphic worms because these worms can change their patterns dynamically. In this paper, a class of neighborhood-relation signatures (NRS) are proposed, including 1-NRS, 2-NRS and (1,2)-NRS. NRS can be used for detecting polymorphic worms since these worms often remain the same relationship between bytes in changing their patterns. Two signature generation algorithm based on Expectation-Maximization(EM) and Gibbs Sampling are designed to generate NRS. We perform extensive experiments to demonstrate the effectiveness of NRS and the correctness of the process of signatures generation. Experiment results show that our approach of defending polymorphic worm based on NRS is more effective than other approach based on existed signatures. 2009 IEEE.

name of conference

  • 2009 11th IEEE International Conference on High Performance Computing and Communications

published proceedings

  • 2009 11th IEEE International Conference on High Performance Computing and Communications

author list (cited authors)

  • Wang, J., Wang, J., Sheng, Y. u., & Chen, J.

citation count

  • 4

complete list of authors

  • Wang, Jie||Wang, Jianxin||Sheng, Yu||Chen, Jianer

publication date

  • January 2009