Nebula - generating syntactical network intrusion signatures
Tillmann Werner, Christoph Fuchs, Elmar Gerhards‐Padilla, Peter Martini · 2009
Signature-based intrusion detection is a state-of-the-art technology for identifying malicious activity in networks. However, attack trends change very fast nowadays, making it impossible to keep up with manual signature engineering. This paper describes a novel concept for automatic signature generation based on efficient autonomous attack classification. Signatures are constructed for each class from syntactical commonalities and go beyond a single, contiguous substring. Each part of a signature is combined with positional information, which drastically improves signature accuracy and matching performance. We argue that a general description of zero-day attacks is immanently restricted to syntactical features and outline how valid signatures for novel real-world attacks were successfully generated.