FREE Registration is required
Overview:
Internet worms pose a serious threat to computer security. Traditional approaches using signatures to detect worms pose little danger to the zero day attacks. The focus of malware research is shifting from using signature patterns to identifying the malicious behavior displayed by the malwares. This paper presents a novel idea of extracting variable length instruction sequences that can identify worms from clean programs using data mining techniques. The analysis is facilitated by the program control flow information contained in the instruction sequences. Based upon general statistics gathered from these instruction sequences one formulated the problem as a binary classification problem and built tree based classifiers including decision tree, bagging and random forest.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 136 KB | |
| Date: | May 2008 | ||
| Pages: | 6 |
Top results from Data Mining - Analysis
» View all Data Mining - Analysis listings
Top results from Knowledge and Data Management
White Papers, Webcasts, and Resources
- Cloud Computing— Latest Buzzword or a Glimpse of the Future? GoogleGo beyond all the hype and decide for yourself whether cloud computing is truly a game changer or just another technology fad.
- Empowerment as a Growth Strategy OracleSee how empowering your customer-facing employees can help you achieve short-term goals plus lay the groundwork for sustainable growth.
- Spend 3 minutes with free EBS ROI Tool - and Save Thousands IBMSee exactly how an Oracle EBS upgrade can lower your cost of ownership, deliver greater business intelligence, and improve capabilities company-wide.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- SmartPlanet
Discover innovative insight and ideas that impact the world around you -
SmartPlanet offers expert advice on innovations in healthcare, including electronic personal health records, treatment, privacy and regulation, and the green technologies that make it happen.
- Learn more >>
- Quest Connect Archive: white papers, demos and more!
-
Did you miss our virtual event? No problem! You can still access the wealth of webcasts, white papers, demos and more? Find everything you need at the Quest Connect archive on demand until Jan 22.
- Learn more >>
Featured Training Courses
Enterprise Applications
- Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
- New Online Dashboard
- Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline









