Detecting and optimizing internet worm traffic signature

Mohammad M. Rasheed, Samir I. Badrawi, Munadil K. Faaeq, Alaa Khaleel Faieq · 2017

Network signatures are used in network intrusion detection systems that try to detect an Internet worm by monitoring network packets. There are many ways to make polymorphic worms. One technique depends on encrypting the body, which erases both signatures and statistical characteristics of the worm byte string. Currently, intrusion detection system reads all the incoming packets and tries to find suspicious patterns known as signatures, by typically using capture techniques. Hence, the proposed technique in this paper focuses on detecting Internet worm and optimizing the worm signature, depending on aspects that do not need a high process to recognize the internet worms. Thus, the result of this proposed technique is detecting and optimizing MSblaster worm traffic.

Read the paper · More papers on PaperTik