loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
22nd Annual Computer Security Applications Conference (ACSAC'06)
NetSpy: Automatic Generation of Spyware Signatures for NIDS
Miami Beach, Florida, USA
December 11-December 15
ISBN: 0-7695-2716-7
Hao Wang, University of Wisconsin-Madison, USA
Somesh Jha, University of Wisconsin-Madison, USA
Vinod Ganapathy, University of Wisconsin-Madison, USA
We present NetSpy, a tool to automatically generate network-level signatures for spyware. NetSpy determines whether an untrusted program is spyware by correlating user input with network traffic generated by the untrusted program. If classified as spyware, NetSpy also generates a signature characterizing the malicious substrate of the spyware?s network behavior. Such a signature can be used by network intrusion detection systems to detect spyware installations in large networks.

In our experiments, NetSpy precisely identified each of the 7 spyware programs that we considered and generated network-level signatures for them. Of the 9 supposedly-benign programs that we considered, NetSpy correctly characterized 6 of them as benign. The remaining 3 programs showed network behavior that was highly suggestive of spying activity.

Citation:
Hao Wang, Somesh Jha, Vinod Ganapathy, "NetSpy: Automatic Generation of Spyware Signatures for NIDS," acsac, pp.99-108, 22nd Annual Computer Security Applications Conference (ACSAC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.