A Novel Immune-Inspired Shellcode Detection Algorithm Based on Hyperellipsoid Detectors
المؤلفون المشاركون
Lu, Tianliang
Zhang, Lu
Fu, Yixian
المصدر
Security and Communication Networks
العدد
المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-10، 10ص.
الناشر
Hindawi Publishing Corporation
تاريخ النشر
2018-02-28
دولة النشر
مصر
عدد الصفحات
10
التخصصات الرئيسية
تكنولوجيا المعلومات وعلم الحاسوب
الملخص EN
Shellcodes are machine language codes injected into target programs in the form of network packets or malformed files.
Shellcodes can trigger buffer overflow vulnerability and execute malicious instructions.
Signature matching technology used by antivirus software or intrusion detection system has low detection rate for unknown or polymorphic shellcodes; to solve such problem, an immune-inspired shellcode detection algorithm was proposed, named ISDA.
Static analysis and dynamic analysis were both applied.
The shellcodes were disassembled to assembly instructions during static analysis and, for dynamic analysis, the API function sequences of shellcodes were obtained by simulation execution to get the behavioral features of polymorphic shellcodes.
The extracted features of shellcodes were encoded to antigens based on n-gram model.
Immature detectors become mature after immune tolerance based on negative selection algorithm.
To improve nonself space coverage rate, the immune detectors were encoded to hyperellipsoids.
To generate better antibody offspring, the detectors were optimized through clonal selection algorithm with genetic mutation.
Finally, shellcode samples were collected and tested, and result shows that the proposed method has higher detection accuracy for both nonencoded and polymorphic shellcodes.
نمط استشهاد جمعية علماء النفس الأمريكية (APA)
Lu, Tianliang& Zhang, Lu& Fu, Yixian. 2018. A Novel Immune-Inspired Shellcode Detection Algorithm Based on Hyperellipsoid Detectors. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-10.
https://search.emarefa.net/detail/BIM-1213957
نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)
Lu, Tianliang…[et al.]. A Novel Immune-Inspired Shellcode Detection Algorithm Based on Hyperellipsoid Detectors. Security and Communication Networks No. 2018 (2018), pp.1-10.
https://search.emarefa.net/detail/BIM-1213957
نمط استشهاد الجمعية الطبية الأمريكية (AMA)
Lu, Tianliang& Zhang, Lu& Fu, Yixian. A Novel Immune-Inspired Shellcode Detection Algorithm Based on Hyperellipsoid Detectors. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-10.
https://search.emarefa.net/detail/BIM-1213957
نوع البيانات
مقالات
لغة النص
الإنجليزية
الملاحظات
Includes bibliographical references
رقم السجل
BIM-1213957
قاعدة معامل التأثير والاستشهادات المرجعية العربي "ارسيف Arcif"
أضخم قاعدة بيانات عربية للاستشهادات المرجعية للمجلات العلمية المحكمة الصادرة في العالم العربي
تقوم هذه الخدمة بالتحقق من التشابه أو الانتحال في الأبحاث والمقالات العلمية والأطروحات الجامعية والكتب والأبحاث باللغة العربية، وتحديد درجة التشابه أو أصالة الأعمال البحثية وحماية ملكيتها الفكرية. تعرف اكثر