ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Conference Paper A Study on Detection of Varied Worms with Analyzing Session Information
Cited - time in scopus Share share facebook twitter linkedin kakaostory
Authors
Il Ahn Cheong, Taek Yong Nam
Issue Date
2006-10
Citation
International Symposium on Information Theory and its Applications (ISITA) 2006, pp.1-4
Language
English
Type
Conference Paper
Abstract
Since many worm attacks appear, more and more varied worms have become a threat to our networks. In this paper, we study to detect these varied worms with analyzing session information from a worm data. We use the session information of a network dump data generated by worm attack and the automatic generation method to generate detection rules that is adequate to find peculiar rules of worm based on entropy theory. As the result, we are able to automatically generate the detection rules of worm attacks and to effectively detect varied worms with the rules.
KSP Keywords
Automatic generation, Detection Rules, Entropy theory, Worm attacks