Analysis Algorithm for the Worm Network Behavior Based on Event Sequence

ZHANG Jia,DUAN Hai-xin,GE Lian-sheng
DOI: https://doi.org/10.3969/j.issn.1671-9352.2007.09.008
2007-01-01
Abstract:As the updating speed of the worm and other malicious codes grows faster and faster,how to analyze large sum of mali-cious sample quickly and effectively becomes an issue of research on internet security.Therefore,an analysis algorithm for worm network behavior based on event sequence was proposed.This algorithm uses the data flow recombination and compression meth-ods to process the pure malicious data.With this procedure,it can get the network behavior profile and the signature of the worm.The application of this algorithm will greatly improve the efficiency of analyzing the worm network behavior,which will be significant for the deployment of firewalls and network invasion detection systems.
What problem does this paper attempt to address?