• DocumentCode
    2034241
  • Title

    A novel approach to worm detection systems

  • Author

    Al-Saawy, Yazed B. ; Cau, Antonio ; Siewe, Francois

  • Author_Institution
    Software Technol. Res. Lab., De Montfort Univ., Leicester, UK
  • fYear
    2015
  • fDate
    28-30 July 2015
  • Firstpage
    1201
  • Lastpage
    1205
  • Abstract
    Computer worms are a type of malicious malware that prey on networked machines. A number of different detection mechanisms have been presented in the literature to detect worms. However, a common drawback of these mechanisms is that any failure to detect the worms results in damaging the real machines. This study proposes a new approach to detection that goes beyond the currently available signature and behavior-based approaches. In contrast to the traditional worm detection system (WDS) that use signature and behavior-based approaches, our proposed approach is based on detection by the damage caused by worms on dummy machines rather than the real machines. The proposed WDS adds additional security as compared to the currently used systems by allowing worms to conduct their normal behavior in a dummy host, thus protecting the rest of the network from damage. The proposed WDS was designed within a network setting and was capable of sending and receiving files and messages between hosts as part of the overall detection mechanism.
  • Keywords
    digital signatures; invasive software; WDS; behavior-based approach; malware; signature-based approach; worm detection system; Databases; Grippers; Internet; Intrusion detection; Malware; Software; Worms detection; behaviour-based; computer security; damage; dummy host; signature-based;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Science and Information Conference (SAI), 2015
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/SAI.2015.7237297
  • Filename
    7237297