Journal on Communications ›› 2014, Vol. 35 ›› Issue (9): 12-19.doi: 10.3969/j.issn.1000-436x.2014.09.002

• PaperⅠ Network attack and Prevention • Previous Articles     Next Articles

Automated polymorphic worm signature generation approach based on seed-extending

Jie WANG,Xiao-xian HE   

  1. School of Information Science and Engineering,Central South University,Changsha 410083,China
  • Online:2014-09-25 Published:2017-06-14
  • Supported by:
    The National Natural Science Foundation of China

Abstract:

A polymorphic worm signature generation approach based on seed-extending,SESG,was proposed.Firstly,algorithm SESG puts all sequences into a queue based on their weight.Seed sequence in the queue is extended,and all kinds of worm sequences and noise sequences are classified.Finally,worm signature is generated from classified worm sequences.Experiments are run to test SESG and compared with other approaches.Experiment results show that SESG can classify worm sequences and noise sequences from suspicious flow pool over other existed approaches,which can generate effective worm signature more easily.

Key words: nformation security, seed-extending algorithm, polymorphic worm, worm detection, worm signature

No Suggested Reading articles found!