作者
Ke Wang, Gabriela Cretu, Salvatore J Stolfo
发表日期
2005/9/7
图书
International Workshop on Recent Advances in Intrusion Detection
页码范围
227-246
出版商
Springer Berlin Heidelberg
简介
New features of the PAYL anomalous payload detection sensor are demonstrated to accurately detect and generate signatures for zero-day worms. Experimental evidence demonstrates that site-specific packet content models are capable of detecting new worms with high accuracy in a collaborative security system. A new approach is proposed that correlates ingress/egress payload alerts to identify the worm’s initial propagation. The method also enables automatic signature generation that can be deployed immediately to network firewalls and content filters to proactively protect other hosts. We also propose a collaborative privacy-preserving security strategy whereby different hosts can exchange PAYL signatures to increase accuracy and mitigate against false positives. The important principle demonstrated is that correlating multiple alerts identifies true positives from the set of anomaly alerts and …
引用总数
2005200620072008200920102011201220132014201520162017201820192020202120222023627414435321614312821302228814733
学术搜索中的文章
K Wang, G Cretu, SJ Stolfo - International Workshop on Recent Advances in …, 2005