LISABETH: automated content-based signature generator for zero-day polymorphic worms

  • Authors:
  • Lorenzo Cavallaro;Andrea Lanzi;Luca Mayer;Mattia Monga

  • Affiliations:
  • Universita degli Studi di Milano, Milan, Italy;Universita degli Studi di Milano, Milan, Italy;Universita degli Studi di Milano, Milan, Italy;Universita degli Studi di Milano, Milan, Italy

  • Venue:
  • Proceedings of the fourth international workshop on Software engineering for secure systems
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Modern worms can spread so quickly that any countermeasure based on human reaction might not be fast enough. Recent research has focused on devising algorithms to automatically produce signature for polymorphic worms, required by Intrusion Detection Systems. However, polymorphic worms are more complex than non-mutating ones as they also require the identification of mutated instances. To this end, we propose Lisabeth, our improved version of Hamsa, an automated content-based signature generation system for polymorphic worms that uses invariant bytes analysis of network traffic content. We show an unknown attack to Hamsa's signature generator that is contrasted by Lisabeth. Moreover, we show that our approach is able to generally improve the resilience to poisoning attacks as supported by our experiments with synthetic polymorphic worms.