Title :
A New Approach to Automatically Detect Worms
Author :
Ping, Wang ; Bin-Xing, Fang ; Xiao-Chun, Yun
Author_Institution :
Harbin Institute of Technology, China
Abstract :
Worms have seriously harmed computer and network systems due to their rapid spread rate. Therefore, it is necessary to research automatic worm detection systems in large networks. In this paper, data stream based anomaly detection is used to screen out anomalous network data flow, subsequently, the signature is extracted. After analyzed, the signature is updated to the misuse detection pattern. Based on an automatic worm defense, a system could discover an epidemic situation effectively and detect an unknown worm.
Keywords :
Computer networks; Computer science; Computer worms; Data mining; Databases; Filters; Internet; Intrusion detection; Pattern analysis; TCPIP;
Conference_Titel :
Parallel and Distributed Computing, Applications and Technologies, 2005. PDCAT 2005. Sixth International Conference on
Print_ISBN :
0-7695-2405-2
DOI :
10.1109/PDCAT.2005.25