Please use this identifier to cite or link to this item: https://repository.cihe.edu.hk/jspui/handle/cihe/1375
DC FieldValueLanguage
dc.contributor.authorChan, Anthony Hing-Hungen_US
dc.contributor.otherMohammed, M. M. Z. E.-
dc.contributor.otherVentura, N.-
dc.date.accessioned2021-08-23T04:54:36Z-
dc.date.available2021-08-23T04:54:36Z-
dc.date.issued2008-
dc.identifier.urihttps://repository.cihe.edu.hk/jspui/handle/cihe/1375-
dc.description.abstractSignature-based intrusion detection systems (IDSs) can be evaded by polymorphic worms which vary their payloads in every infection attempt. In this paper, we propose Honeycyber, a system for automated signature generation for zero-day polymorphic worms. We have designed a novel double-Honeynet system, which is able to automatically detect new worms and isolate the attack traffic from innocuous traffic. We introduce unlimited Honeynet outbound connections, which allow us to capture different payloads in every infection of the same worm. The system is able to generate signatures to match most polymorphic worm instances with low false positives and low false negatives.en_US
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.titleHoneycyber: Automated signature generation for zero-day polymorphic wormsen_US
dc.typeconference proceedingsen_US
dc.relation.publicationProceedings of the 2008 IEEE Military Communications Conference (MILCOM)en_US
dc.identifier.doi10.1109/MILCOM.2008.4753178-
dc.contributor.affiliationSchool of Computing and Information Sciencesen_US
dc.relation.isbn9781424426768en_US
dc.description.startpage980-
dc.description.endpage985-
dc.cihe.affiliatedNo-
item.languageiso639-1en-
item.fulltextNo Fulltext-
item.openairetypeconference proceedings-
item.grantfulltextnone-
item.openairecristypehttp://purl.org/coar/resource_type/c_5794-
item.cerifentitytypePublications-
crisitem.author.deptYam Pak Charitable Foundation School of Computing and Information Sciences-
crisitem.author.orcid0000-0001-7479-0787-
Appears in Collections:CIS Publication
SFX Query Show simple item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.