Generation of Trojan communication signatures based on support

Xiaoyan Sun,Yun Dong Xing,Shengli Liu,Yuefei Zhu
2010-01-01
Abstract:Either current generation methods of network attack signature are not suitable for Trojan communication signature generation, or generation time overhead is too large. To address these problems, the definitions of group support and distinction signature and the criteria for determining noise were put forward. The algorithm of Trojan network communication signature generation based on support was given, and the theoretical higher limit of the number of two-sequence alignment was analyzed. Experimental results show that the algorithm based on support can reduce the number of two-sequence alignment, and the generated signatures have good accuracy.
What problem does this paper attempt to address?