Characterizing and detecting virus replication Conference

Morales, JA, Clarke, PJ, Deng, Y. (2008). Characterizing and detecting virus replication . 214-219. 10.1109/ICONS.2008.37

cited authors

  • Morales, JA; Clarke, PJ; Deng, Y

authors

abstract

  • Newly released computer viruses are spreading faster than ever before and current signature based detection do not protect against these unknown viruses. This paper presents a characterization of virus replication. Two detection models are developed, one using operation sequence matching and the other using frequency measures. The research shows virus replication can be characterized and used to detect known and unknown viruses with minimal false negatives. In our testing using operation sequence matching, over 250 viruses were detected with 43 subsequences. Detection of 130 viruses, 45% of all tested viruses, occured with the replication sequence of just one virus. Our testing using frequency measures detected all test viruses with no false negatives. © 2008 IEEE.

publication date

  • September 5, 2008

Digital Object Identifier (DOI)

start page

  • 214

end page

  • 219