An automated signature generation approach for polymorphic worm based on color coding

  • Authors:
  • Jie Wang;Jianxin Wang;Jianer Chen;Xi Zhang

  • Affiliations:
  • School of Information Science and Engineering, Central South University, Changsha, China;School of Information Science and Engineering, Central South University, Changsha, China;School of Information Science and Engineering, Central South University, Changsha, China;Department of Electrical and Computer Engineering, Texas A&M University, Texas

  • Venue:
  • ICC'09 Proceedings of the 2009 IEEE international conference on Communications
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

In order to prevent worms from propagating rapidly, it is essential to generate worm signatures quickly and accurately. However, most of recent approaches can not generate accurate signatures for polymorphic worms in environments with noise. In this paper, we present a signature generation algorithm, namely CCSF (Color Coding Signature Finding), for polymorphic worms based on color coding. CCSF divides n sequences into m groups and each group contains 20 sequences. Firstly, CCSF generates signatures for each group by adopting color coding and filters them. Then all reserved signatures are clustered to get rid of redundant substrings. In this approach, signature can be generated without any fragment in environments with noise, and it can be used in IDS (Intrusion Detection System) to detect polymorphic worm. We perform extensive experiments to demonstrate the effectiveness of our approach. Experiment results show distinct advantages in generating accurate signatures over other existed approaches.