Detection of Unknown Computer Worms Activity Based on Computer Behavior using Data Mining

Honolulu, HI(2007)

引用 25|浏览44
暂无评分
摘要
Detecting unknown worms is a challenging task. Extant solutions, such as anti-virus tools, rely mainly on prior explicit knowledge of specific worm signatures. As a result, after the appearance of a new worm on the Web there is a significant delay until an update carrying the worm's signature is distributed to anti-virus tools. During this time interval a new worm can infect many computers and cause significant damage. We propose an innovative technique for detecting the presence of an unknown worm, not necessarily by recognizing specific instances of the worm, but rather based on the computer measurements. We designed an experiment to test the new technique employing several computer configurations and background applications activity. During the experiments 323 computer features were monitored. Four feature selection techniques were used to reduce the amount of features and four classification algorithms were applied on the resulting feature subsets. Our results indicate that using this approach resulted in an above 90% average accuracy, and for specific unknown worms accuracy reached above 99%, using just 20 features while maintaining a low level of false positive rate .
更多
查看译文
关键词
computer viruses,invasive software,world wide web,antivirus tools,computer behavior,computer configurations,unknown worms detection,pattern classification,computer measurements,internet,unknown computer worms activity,specific worm signatures,data mining,background applications activity,feature selection,computer worm detection,background application activity,classification algorithms,false positive rate,computer worm,explicit knowledge
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要