作者: Jie Wang , Xiaoxian He
DOI: 10.1007/978-3-319-27137-8_28
关键词:
摘要: Because of complex polymorphism in worms and the disturbance crafted noises, it becomes more difficult to generate signatures quickly accurately. This paper proposes a neighbor relation signature (NRS) for polymorphic worms,which is collection distance frequency distributions between byte. Moreover, we propose generation algorithm (NRS-CC) by combing NRS color coding technique. NRS-CC selects sequences randomly from suspicious flow pool signatures, then uses technique get rid noise disturbance. Extensive experiments are carried out demonstrate validity our approach. The experiment results show that approach can compared with existing approaches when contains sequences.