作者: Yong Tang , Xicheng Lu , Bin Xiao
DOI: 10.1007/978-3-540-73547-2_49
关键词:
摘要: It is crucial to automatically generate accurate and effective signatures defense against polymorphic worms. Previous work using conjunctions of tokens or token subsequence could lose some important information, like ignoring 1 byte neglecting the distances in sequential tokens. In this paper we propose Simplified Regular Expression (SRE) signature, present its signature generation method based on multiple sequence alignment algorithm. The algorithm extended from pairwise algorithm, which encourages contiguous substring extraction able support wildcard string preserve distance invariant content segment generated SRE signatures. Thus, can express information for worms, turn makes even extracted worms become valuable. Experiments several types show that, compared with by current network-based systems (NSGs), are more precise match