Publication | Closed Access
A data mining approach for analysis of worm activity through automatic signature generation
12
Citations
21
References
2008
Year
Unknown Venue
Anomaly DetectionEngineeringInformation SecurityData Mining ApproachInformation ForensicsComputer WormsWorm ActivitySoftware AnalysisData ScienceData MiningSystems EngineeringNovel FrameworkIntrusion Detection SystemThreat DetectionIntrusion ToleranceKnowledge DiscoveryComputer ScienceNetwork ForensicsAutomatic Signature GenerationAnti-virus TechniqueIntrusion DetectionBotnet DetectionMalware Analysis
This paper proposes a novel framework to automatically discover and analyze traffic generated by computer worms and other anomalous behaviors that interact with a non-solicited traffic monitoring system. Network packets are analyzed by an Intrusion Detection System (IDS), and new signatures are generated clustering those which remain unknown for the IDS. Furthermore, the framework provides a mechanism to cluster the alarms produced by the IDS producing a correlated vision of the traffic observed. Both the automatic signature generation and the alarm clusters are accomplished using data mining techniques.
| Year | Citations | |
|---|---|---|
Page 1
Page 1