Download now Free registration required
This paper proposes an automated approach for quickly detecting previously unknown worms and viruses based on two key behavioral characteristics a common exploit sequence together with a range of unique sources generating infections and destinations being targeted. More importantly, this approach is called "Content Sifting" automatically generates precise signatures that can then be used to filter or moderate the spread of the worm elsewhere in the network.
- Format: PDF
- Size: 546.6 KB