PolyI-D: polymorphic worm detection based on instruction distribution

  • Authors:
  • Ki Hun Lee;Yuna Kim;Sung Je Hong;Jong Kim

  • Affiliations:
  • Department of Computer Science and Engineering, Pohang University of Science and Technology, Pohang, Korea;Department of Computer Science and Engineering, Pohang University of Science and Technology, Pohang, Korea;Department of Computer Science and Engineering, Pohang University of Science and Technology, Pohang, Korea;Department of Computer Science and Engineering, Pohang University of Science and Technology, Pohang, Korea

  • Venue:
  • WISA'06 Proceedings of the 7th international conference on Information security applications: PartI
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

With lack of diversity in platforms and softwares running in Internet-attached hosts, Internet worms can spread all over the world in just a few minutes. Many researchers suggest the signature-based Network Intrusion Detection System(NIDS) to defend the network against it. However, the polymorphic worm evolved from the traditional Internet worm was devised to evade signature-based detection schemes, which actually makes NIDS useless. Some schemes are proposed for detecting it, but they have some shortcomings such as belated detection and huge overhead. In this paper, we propose a new system, called PolyI-D, that detects the polymorphic worm through some tests based on instruction distribution in real-time with little overhead. This is particularly suitable even for fast spread and continuously mutated worms.