Dissertation > Excellent graduate degree dissertation topics show

Research on Bahavior-Based Polymorphic Worms Detection Technology

Author: XuXiaoMeng
Tutor: XuQiuLiang
School: Shandong University
Course: Applied Computer Technology
Keywords: Polymorphic worms Behavior-based detection Changes in program structure Control flow chart Program dependence graph
CLC: TP393.08
Type: Master's thesis
Year: 2008
Downloads: 95
Quote: 0
Read: Download Dissertation

Abstract


With the application of network systems and the increasing complexity of network worms become important threat to network security. In recent years, the worm itself, there has been new progress, that polymorphic worms appear, by using a variety of deformation can easily avoid detection of the existing intrusion detection systems, as future threats to the security of the Internet significant risks. At present, the polymorphic worm detection technology has become a the worm research focus. Polymorphic worm has been a lot of valuable research results, but are established in a polymorphic worm only simple deformation and hidden assumptions based on lack of a comprehensive analysis and understanding of existing worm deformation techniques and instruments . Although the polymorphic worm is not yet on the network large-scale and like Morris, CodRed worms as a huge loss and danger to society, but with the continuous improvement of the code obfuscation and deformation techniques, potentially damaging and the dangers have to concern us. This paper attempts to polymorphic worm detection technology as the theme, its systematic and comprehensive analysis and research. Polymorphic worm detection technology based on the behavior, due to its worm behavior invariance this feature as well as the flexibility in detecting polymorphic worm has become the focus of the study polymorphic worm detection technology. This paper discusses the the polymorphic worm itself the structure and common deformation technology in recent years for polymorphic worm control techniques are summarized and comparative analysis, and on this basis, the polymorphic worm itself further research study and make a more polymorphic worm detection method, made as follows: 1) a systematic and comprehensive analysis of existing polymorphic worm detection technology gives. Comparison of the existing categories of detection technology, given their respective advantages and limitations, and in graphical form clear and comprehensive have their individual characteristics were compared and summarized. 2) gives an ability polymorphic worm structure and deformation - polymorphic worm can change the structure of the program. Through the analysis of a large number of literature and existing deformation techniques, ability and potentially harmful polymorphic worms, and a variety of deformation. The same time, the article also showed the limitations of the existing detection technology in the prevention and treatment of the polymorphic worms analyzed and summarized. 3) for the polymorphic worm, a new detection technology - PDG (program dependence graph) detection structure variable polymorphic worms. In-depth analysis of the behavior characteristics of the worm, that is in the process of the spread and attack functionality remains the same characteristics, proposed to PDG to describe the common features between the different forms of worms instance, in order to detect the polymorphic worms. In this paper, the development of polymorphic worms technology provides a new way of thinking, that the variable structure of polymorphic worms, and the detection method. Through experimentation and testing, this method has good detection capabilities and low error, and acceptable detection efficiency.

Related Dissertations

  1. The Design and Implementation of Website Malice Assessing System,TP393.092
  2. The Research and Applications of Instruction Criticality in Processors,TP332
  3. Software Testing Based on Data Mining Technology,TP311.52
  4. Zero-day attacks polymorphic worm detection model,TP393.08
  5. Research on Constructing of System Information Flow Graph Based on Dependence Graph,TP311.5
  6. The design and implementation of the detection and alarm system based on Trojan behavior characteristics,TP393.08
  7. Asynchronous collaborative programming semantics - based version merger,TP311.11
  8. Research on Static and Dynamic Combined Analysis in Object-Oriented Reverse Engineering,TP391.7
  9. Generating of Static Call Graph and Use Case Model,TP311.11
  10. Research on Conceptual Design of Mechatronic System of Chinese Traditional Pills Machine,TH788
  11. Research on the Methods of Java Code Clone Detecting,TP312.1
  12. Research of IRC Botnet Detection Based on Behavior,TP393.08
  13. Research on the Impact Analysis of Network Security Incidents Based on Simulation,TP393.08
  14. Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
  15. The Research on Intrusion Detection System Based on Machine Learning,TP393.08
  16. Research on Credential Chain Discovery Mechanism Based on Improved Role-based Trust Management Language,TP393.08
  17. Research on Service Type-Oriented E-commerce Trust Model,TP393.08
  18. IPsec-based remote access to corporate network systems design and implementation,TP393.08
  19. Zombie control behavior recognition and detection method of,TP393.08
  20. Peer network of trust mechanism,TP393.08
  21. FSVM -based data mining method and its application to intrusion detection research,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile