Large Scale Network Worm Detection Using Automatic Signature Extraction

WANG Ping,FANG Bin-xing,YUN Xiao-chun
DOI: https://doi.org/10.3321/j.issn:1000-436x.2006.06.013
2006-01-01
Abstract:Worms had done serious harm to the computer networks due to their propagating speeds.The research was necessary to detect worms quickly and automatically.In large scale networks,flux based anomaly found module was used to screen out anomalous network data set,and automatic signature extraction was processed in succession,then its signa-ture was updated to the signature database of the signature based detection module,thus,the approach to detect unknown worms was realized.Novel epidemic can be found effectively,and the whole system is the fundament of worm automatic defense.
What problem does this paper attempt to address?