DocumentCode :
2311718
Title :
Detection of Worm Propagation Engines in the System Call Domain using Colored Petri Nets
Author :
Tokhtabayev, Arnur G. ; Skormin, Victor A. ; Dolgikh, Andrey M.
Author_Institution :
Center for Adv. Inf. Technol., Binghamton Univ., Binghamton, NY
fYear :
2008
fDate :
7-9 Dec. 2008
Firstpage :
59
Lastpage :
68
Abstract :
While network worms carry various payloads and may utilize any available exploits, they all have one common component - the propagation engine. Moreover, it is important to note that the number of conceptually distinct propagation engines employed by existing network worms is quite limited. This paper presents a novel signature-based approach for detecting attacks perpetrated by network worms as a manifestation of a semantic functionality performed by one of the few known propagation engines. We propose a novel methodology to recognize any semantic functionality in the system call domain through utilizing colored Petri Nets. In this application, Petri Nets embody behavior-based signatures of the propagation engine functionalities. These signatures are indicative of the shell code activity in the first stage of the worm proliferation. We developed, tested and evaluated a propagation engine detector (PED) system that detects activity of the worm shell code executed by a process during an attack. Moreover, PED is able to recognize the type of propagation engine employed by the attacking worm.
Keywords :
Petri nets; digital signatures; graph colouring; invasive software; behavior-based signatures; colored Petri nets; network worms; propagation engine detector system; signature-based approach; system call domain; worm proliferation; worm propagation engines; worm shell code; Capacitive sensors; Code standards; Detectors; Engines; Functional programming; Image databases; Information technology; Payloads; Petri nets; System testing; Colored Petri Nets; IDS; Propagation engine; System calls;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
Conference_Location :
Austin, Texas
ISSN :
1097-2641
Print_ISBN :
978-1-4244-3368-1
Electronic_ISBN :
1097-2641
Type :
conf
DOI :
10.1109/PCCC.2008.4745108
Filename :
4745108
Link To Document :
بازگشت