|
The development of the Internet has changed the lives of people working mode, an endless stream of online news, online shopping, tele-education, e-commerce and other applications, a new, full of opportunities and challenges of the digital world is evolving reality. In the digital world, the information, especially credit card, e-mail address and other private information, not only is an important asset, but has become a salable commodity. According to statistics, the underground trading system for sale of such goods (such as credit card information, e-mail address book or game account, etc.) of the total value of more than 276 million U.S. dollars, which most commonly sold credit card information potential total value of up to $ 5.3 billion. An important means of access to such goods using malicious software. The spread on the Internet in 2007, there are records of malicious software (including worms, Trojans, etc.), the number reached 2,227,415, turned up nearly four-fold compared with 2006, in which 70% of the malicious software to steal confidential information. Some characteristics of infectious diseases malicious code can be instantaneous spyware, Trojan, Rootkit theft software as its load (Payload) to send to the huge amount of machines on the Internet, complete the collection of sensitive information, or even the entire Internet destruction, has attracted wide attention from researchers. Compared with malware worm has its own characteristics: the worm is spread through the network, it can spread quickly, the harm is greater: January 26, 2003, a computer named 2003 worms King virus spread rapidly and attacked the global severely clogged, resulting in the Internet network, DNS paralysis caused significantly slow down the speed of Internet users browse Internet web pages and e-mail while interrupt the operation of the ATMs, airline tickets and other network reservation system outage , such as credit card payment and collection system fails, it is estimated that the direct economic losses caused by this virus in at least $ 1.2 billion. Malware and network worm is the biggest threat to Internet security. Therefore, the detection of malicious software, and network worms is an important research topic in information security. One of this paper is to propose a new method of malware detection - API-based machine learning methods: first capture the program is running, the key API calls, and then 4-Gram thoughts and information gain feature extraction, last call 2 - level of BKS algorithm for the integration of multi-view classification. Testing to prove the correct rate of classification and malware detection and classification of malicious software. Another work of this article is proposed a vulnerability-based automatic worm signature generation technology - PASG (Protocol Aware Signature Generation). PASG captured by extracting network worm attack network and host information through the longest common subsequence string, database training and protocol analysis-based technology automatically generates a line with the characteristics of the intrusion detection system Snort requirements, this feature is not only effective Characterization of worms, and to some extent, be able to identify the other worms attack the same vulnerability. Tests proved, features, although the length is relatively short, but the false alarm rate, the correct rate.
|