Profiling self-propagating worms via behavioral footprinting

  • Authors:
  • Xuxian Jiang;Dongyan Xu

  • Affiliations:
  • George Mason University, Fairfax, VA;Purdue University, West Lafayette, IN

  • Venue:
  • Proceedings of the 4th ACM workshop on Recurring malcode
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes behavioral footprinting, a new dimension of worm profiling based on worm infection sessions. A worm's infection session contains a number of steps (e.g., for probing, exploitation, and replication) that are exhibited in certain order in every successful worm infection. Behavioral footprinting complements content-based signature by enriching a worm's profile, which will be used in worm identification, an important task in post worm attack investigation and recovery. We propose an algorithm to extract a worm's behavioral footprint from the worm's traffic traces. Our evaluation with a number of real worms and their variants confirms the existence of worms' behavioral footprints and demonstrates their effectiveness in worm identification.