Signature metrics for accurate and automated worm detection
WORM, pp. 65-72, 2006.
automated worm detectionuniversity trafficautomated payload fingerprintingzotob outbreakfalse positiveMore(8+)
This paper presents two simple algorithms, TreeCount and SenderCount that detect a broad range of exploit-based and email worms, respectively. These algorithms, when combined with automated payload fingerprinting, generate precise worm payload signatures. We show that fundamental traffic properties of most worms, such as infected hosts' a...More
PPT (Upload PPT)