The Design and Testing of Automated Signature Generation Engine for Worms Detection

  • Authors:
  • Sijung Kim;Geuk Lee;Bonghan Kim

  • Affiliations:
  • Dept. of Computer Science, ChungJu National University, Chungju , Chungbuk, Korea;Dept. of Computer Engineering, Hannam University, Taejeon, Korea;Dept. of Computer & Information Engineering, Chongju University, Chongju, Chungbuk, Korea

  • Venue:
  • KES-AMSTA '07 Proceedings of the 1st KES International Symposium on Agent and Multi-Agent Systems: Technologies and Applications
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

We have proposed automated signature generation engine for unknown attack detection. For this proposal, we have studied signature engine divided into header field and payload field. Especially, in payload field, we proposed signature generation agent which can be presented by using Suffix tree, and Longest Common Subsequence(LCSeq) among them is used to generate new signature automatically. Through the test, Snort signature and generated signature by using Longest Common Subsequence(LCSeq) are compared and evaluated.