Please use this identifier to cite or link to this item: https://repository.cihe.edu.hk/jspui/handle/cihe/1372
DC FieldValueLanguage
dc.contributor.authorChan, Anthony Hing-Hungen_US
dc.contributor.otherMohammed, M. M. Z. E.-
dc.date.accessioned2021-08-23T04:31:32Z-
dc.date.available2021-08-23T04:31:32Z-
dc.date.issued2008-
dc.identifier.urihttps://repository.cihe.edu.hk/jspui/handle/cihe/1372-
dc.description.abstractPolymorphic worms evade signature-based intrusion detection systems (IDSs) by varying their payloads on every infection attempt. In this paper, we propose a system for automated signature generation for polymorphic worms. We design a novel double-honeynet system which is able to automatically detect unknown polymorphic worms. We propose signatures with multiple substrings to match most of the worm instances with low false positives and low false negatives. Our system applies signature-based detection, protocol anomaly detection, and protocol semantics awareness to the network traffic that is captured by the double-honeynet.en_US
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.titleFast automated signature generation for polymorphic worms using double-honeyneten_US
dc.typeconference proceedingsen_US
dc.relation.publicationProceedings of the 2008 Third International Conference on Broadband Communications, Information Technology & Biomedical Applications (BROADCOM)en_US
dc.identifier.doi10.1109/BROADCOM.2008.21-
dc.contributor.affiliationSchool of Computing and Information Sciencesen_US
dc.relation.isbn9781424432813en_US
dc.description.startpage142en_US
dc.description.endpage147en_US
dc.cihe.affiliatedNo-
item.languageiso639-1en-
item.fulltextNo Fulltext-
item.openairetypeconference proceedings-
item.grantfulltextnone-
item.openairecristypehttp://purl.org/coar/resource_type/c_5794-
item.cerifentitytypePublications-
crisitem.author.deptYam Pak Charitable Foundation School of Computing and Information Sciences-
crisitem.author.orcid0000-0001-7479-0787-
Appears in Collections:CIS Publication
SFX Query Show simple item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.