TY - GEN
T1 - An approach for classifying internet worms based on temporal behaviors and packet flows
AU - Lee, Min-Soo
AU - Shon, Taeshik
AU - Cho, Kyuhyung
AU - Chung, Manhyun
AU - Seo, Jungtaek
AU - Moon, Jongsub
PY - 2007/12/1
Y1 - 2007/12/1
N2 - With the growth of critical worm threats, many researchers have studied worm-related topics and internet anomalies. The researches are mainly concentrated on worm propagation and detection more than the fundamental characteristics of worms. It is very important to know worms' characteristics because the characteristics provide basic resource for worm prevention. Unfortunately, this kind of research cases are very few until now. Moreover the existing researches only focus on understanding the function structure of the worm propagation or the taxonomy of the worm according to a sequence of worm attacks. Thus, in this paper, we try to confirm the formalized pattern of the worm action from the existing researches and analyze the report of the anti-virus companies. Finally, we define the formalized actions based on temporal behaviors and worm packet flows, and we apply our proposed method for the new worm classification.
AB - With the growth of critical worm threats, many researchers have studied worm-related topics and internet anomalies. The researches are mainly concentrated on worm propagation and detection more than the fundamental characteristics of worms. It is very important to know worms' characteristics because the characteristics provide basic resource for worm prevention. Unfortunately, this kind of research cases are very few until now. Moreover the existing researches only focus on understanding the function structure of the worm propagation or the taxonomy of the worm according to a sequence of worm attacks. Thus, in this paper, we try to confirm the formalized pattern of the worm action from the existing researches and analyze the report of the anti-virus companies. Finally, we define the formalized actions based on temporal behaviors and worm packet flows, and we apply our proposed method for the new worm classification.
KW - Taxonomy of worm
KW - Temporal behavior
KW - Ubiquitous security
KW - Worm packet flows
UR - http://www.scopus.com/inward/record.url?scp=38049088466&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=38049088466&partnerID=8YFLogxK
M3 - Conference contribution
AN - SCOPUS:38049088466
SN - 9783540741701
VL - 4681 LNCS
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 646
EP - 655
BT - Advanced Intelligent Computing Theories and Applications
T2 - 3rd International Conference on Intelligent Computing, ICIC 2007
Y2 - 21 August 2007 through 24 August 2007
ER -