• DocumentCode
    3704126
  • Title

    A Method for Deriving and Testing Malicious Behavior Detection Rules

  • Author

    Raimo Hilden; Hätönen

  • Author_Institution
    IAM Consulting, Trusteq, Espoo, Finland
  • Volume
    1
  • fYear
    2015
  • Firstpage
    1337
  • Lastpage
    1342
  • Abstract
    The internet is riddled with numerous malware and other threats. This puts the limited resources of network security devices, such as firewalls and intrusion detection systems, under growing stress. They have to cope with increasing network traffic and manage numerous detection rules for threatening traffic. Creating covering set of detection rules manually is a slow and tedious process. In this paper, we present a method to automatically create detection rules for an intrusion detection system from interaction signatures of known malware. Our method maintains information integrity and reports potential issues during the derivation process. The method was tested with HTTP traffic generated from known malware signatures using Snort as the IDS rule-engine.
  • Keywords
    "Redundancy","Testing","Malware","Telecommunication traffic","Syntactics","Intrusion detection","Optimization"
  • Publisher
    ieee
  • Conference_Titel
    Trustcom/BigDataSE/ISPA, 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/Trustcom.2015.527
  • Filename
    7345435