An automated signature generation approach for polymorphic worm based on color coding
Download
1 / 12

An Automated Signature Generation Approach for Polymorphic Worm Based on Color Coding - PowerPoint PPT Presentation


  • 84 Views
  • Uploaded on

An Automated Signature Generation Approach for Polymorphic Worm Based on Color Coding. Jie Wang; Jianxin Wang; Jianer Chen; Xi Zhang; IEEE International Conference on Communications, 2009. ICC '09. Reporter: Luo Sheng-Yuan 2009/11/12. Outline. Introduction Related Work Proposed Scheme

loader
I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
capcha
Download Presentation

PowerPoint Slideshow about ' An Automated Signature Generation Approach for Polymorphic Worm Based on Color Coding' - london


An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
An automated signature generation approach for polymorphic worm based on color coding

An Automated Signature Generation Approach for Polymorphic Worm Based on Color Coding

Jie Wang; Jianxin Wang; Jianer Chen; Xi Zhang;

IEEE International Conference on Communications, 2009. ICC '09.

Reporter: Luo Sheng-Yuan 2009/11/12


Outline
Outline Worm Based on Color Coding

  • Introduction

  • Related Work

  • Proposed Scheme

  • Experiments Result

  • Conclusion


Introduction
Introduction Worm Based on Color Coding

  • Previous approaches can generate signature for worm without noise disturbance, but they all have trouble in generating worm signature with noise.


Related work
Related Work Worm Based on Color Coding

  • Polygraph’s Scheme

    • Token Signature


Related work1
Related Work Worm Based on Color Coding

  • Polygraph’s Scheme

    • Token-subsequence Signature

      • consists of ordered list of tokens

    • Conjunction Signature

      • consists of an unordered set of tokens

    • Bayes Signature

      • consists of a set of tokens, each token is associated with a score


Proposed scheme
Proposed Scheme Worm Based on Color Coding

  • Color Coding

    • 5 items, 4 colors

    • There must be 2 items with same color.


Proposed scheme1
Proposed Scheme Worm Based on Color Coding

  • CCSF(Color Coding Signature Finding)

    • Divides n sequences into m groups and each group contains 20 sequences.

Suspicious Pool

(n sequence)

………………………………

20

20

20

20


Proposed scheme2
Proposed Scheme Worm Based on Color Coding

  • CCSF

    • Color Coding


Proposed scheme3
Proposed Scheme Worm Based on Color Coding

  • CCFS

    • Extracts Common Substrings(Tokens)

Sequence1

H

e

l

l

o

W

o

r

l

d

Sequence2

H

e

l

l

o

h

W

o

r

l

d

r

u

1 scan

2 scan

Sequencek

H

e

l

l

o

t

W

o

r

l

d

h


Experiments result
Experiments Result Worm Based on Color Coding

  • Signature generation with some noise sequences.

    • Correct Signature


Experiments result1
Experiments Result Worm Based on Color Coding

  • Signature generation with some noise sequences.

    • Accurate Signature


Conclusion
Conclusion Worm Based on Color Coding

  • CCSF is able to generate signatures automatically for polymorphic worms in the environments with noise.

  • In this paper, only one worm type of a suspicious flow pool is considered in CCSF.


ad