An architecture of unknown attack detection system against zero-day worm

  • Authors:
  • Ikkyun Kim;Daewon Kim;Byoungkoo Kim;Yangseo Choi;Seongyong Yoon;Jintae Oh;Jongsoo Jang

  • Affiliations:
  • Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea;Electronics and Telecommunication Research Institute, Information Security Research Division, Daejeon, South Korea

  • Venue:
  • ACS'08 Proceedings of the 8th conference on Applied computer scince
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We have introduced the ZASMIN (Zeroday-Attack Signature Management Infrastructure) system, which is developed for novel network attack detection. This system provides early warning at the moment the attacks start to spread on the network and to block the spread of the cyber attacks by automatically generating a signature that could be used by the network security appliance such as IPS. This system have adopted various of new technologies -- suspicious traffic monitoring, attack validation, polymorphic worm recognition, signature generation -- for unknown network attack detection. Because its hardware-based accelerator is also capable to deal with giga-bit speed traffic, it can be applicable to Internet backbone or the bottle-neck point of high-speed enterprise network without any loss of traffic. In this paper, after we setup the ZASMIN to real testbed, we have analyzed the results of the ZASMIN about detection of unknown attack.