A novel anomaly detection algorithm and prewarning technology of unknown worms

Xiaojun Tong,Zhu Wang
DOI: https://doi.org/10.1007/978-3-642-25002-6_23
2011-01-01
Abstract:The existing worm detection system requires high detection environment and has high false alarm rate. So the paper proposed a novel anomaly detection algorithm and the prewarning technology of unknown network worms. We detect unknown worms by means of multidimensional worm abnormal detection method to discover unknown worms, extracts unknown worm features set by analyzing worm data in a leap-style way and creates new rules which will be used to detect the corresponding worm in case that the unknown worm attacks again. Experiments have proved that this method can discover new worms successfully, extracts corresponding features and creates new rules for later detection. Experiment data has shown that this method has a high success detection rate and low false alarm rate.
What problem does this paper attempt to address?