Homology analysis method of worms based on attack and propagation features

Liyan Wang, Jingfeng Xue, Yan Cui, Yong Wang, Chun Shan*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Citation (Scopus)

Abstract

Internet worms pose a serious threat to the Internet security. In order to avoid the security detection and adapt to diverse target environment, the attackers often modify the existing worm code, then get the variants of original worm. Therefore, it is of practical significance to determine the cognate relationship between worms quickly and accurately. By extracting the semantic structure, attack behavior and propagation behavior of the worm, the worm feature set is generated, and the worm sensitive behavior library is built with the idea of association analysis. On this basis, combined with random forest and sensitive behavior matching algorithm, the homology relationship between worms was determined. The experimental results show that the method proposed can fully guarantee the time performance of the algorithm, what’s more further improve the accuracy of the results of the homology analysis of worms.

Original languageEnglish
Title of host publicationTrusted Computing and Information Security - 11th Chinese Conference, CTCIS 2017, Proceedings
EditorsFei Yan, Ming Xu, Shaojing Fu, Zheng Qin
PublisherSpringer Verlag
Pages1-15
Number of pages15
ISBN (Print)9789811070792
DOIs
Publication statusPublished - 2017
Event11th Chinese Conference on Trusted Computing and Information Security, CTCIS 2017 - Changsha, China
Duration: 14 Sept 201717 Sept 2017

Publication series

NameCommunications in Computer and Information Science
Volume704
ISSN (Print)1865-0929

Conference

Conference11th Chinese Conference on Trusted Computing and Information Security, CTCIS 2017
Country/TerritoryChina
CityChangsha
Period14/09/1717/09/17

Keywords

  • Feature engineering
  • Frequent pattern mining
  • Homology analysis
  • Sensitive behavior match
  • Worm

Fingerprint

Dive into the research topics of 'Homology analysis method of worms based on attack and propagation features'. Together they form a unique fingerprint.

Cite this