2008 Third International Conference on Availability, Reliability and Security Detection of Malcodes by Packet Classification March 04-March 07 ISBN: 978-0-7695-3102-1
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ARES.2008.100
In this paper, we propose an anomaly detection approach that classifies packets into code-type and data-type. Our objective is to detect a packet containing codes flowing into a network port, which normally expects data packets only. The proposed approach can detect potentially malicious packets such as worms, viruses, and shellcodes. We propose a time-efficient algorithm and show the results of our initial experiments.
Citation:
Irfan Ahmed, Kyung-suk Lhee, "Detection of Malcodes by Packet Classification," ares, pp.1028-1035, 2008 Third International Conference on Availability, Reliability and Security, 2008 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||