Signature metrics for accurate and automated worm detection
WORM, pp. 65-72, 2006.
This paper presents two simple algorithms, TreeCount and SenderCount that detect a broad range of exploit-based and email worms, respectively. These algorithms, when combined with automated payload fingerprinting, generate precise worm payload signatures. We show that fundamental traffic properties of most worms, such as infected hosts' a...More
PPT (Upload PPT)