Automated signature generation for Zero-day polymorphic worms using a Double-honeynet

dc.contributor.advisorChan, H Anthonyen_ZA
dc.contributor.authorMohammed, Mohssen M Z Een_ZA
dc.date.accessioned2015-01-04T14:20:13Z
dc.date.available2015-01-04T14:20:13Z
dc.date.issued2012en_ZA
dc.descriptionIncludes bibliographical references.en_ZA
dc.description.abstractThis thesis proposes an accurate system for signature generation for Zero-day polymorphic worms. Thesis consists of two parts: In part one, polymorphic worm instances are collected by designing a novel Double-honeynet system, which is able to detect new worms that have not been seen before. Unlimited honeynet outbound connections are introduced to collect all polymorphic worm instances. Therefore this system produces accurate worm signatures. In part two, signatures are generated for the polymorphic worms that are collected by the Double-honeynet system. Both a Modified Knuth-Morris-Pratt (MKMP) Algorithm, which is string matching based, and a Modified Principal Component Analysis (MPCA), which is statistics based, are used.en_ZA
dc.identifier.apacitationMohammed, M. M. Z. E. (2012). <i>Automated signature generation for Zero-day polymorphic worms using a Double-honeynet</i>. (Thesis). University of Cape Town ,Faculty of Engineering & the Built Environment ,Department of Electrical Engineering. Retrieved from http://hdl.handle.net/11427/11233en_ZA
dc.identifier.chicagocitationMohammed, Mohssen M Z E. <i>"Automated signature generation for Zero-day polymorphic worms using a Double-honeynet."</i> Thesis., University of Cape Town ,Faculty of Engineering & the Built Environment ,Department of Electrical Engineering, 2012. http://hdl.handle.net/11427/11233en_ZA
dc.identifier.citationMohammed, M. 2012. Automated signature generation for Zero-day polymorphic worms using a Double-honeynet. University of Cape Town.en_ZA
dc.identifier.ris TY - Thesis / Dissertation AU - Mohammed, Mohssen M Z E AB - This thesis proposes an accurate system for signature generation for Zero-day polymorphic worms. Thesis consists of two parts: In part one, polymorphic worm instances are collected by designing a novel Double-honeynet system, which is able to detect new worms that have not been seen before. Unlimited honeynet outbound connections are introduced to collect all polymorphic worm instances. Therefore this system produces accurate worm signatures. In part two, signatures are generated for the polymorphic worms that are collected by the Double-honeynet system. Both a Modified Knuth-Morris-Pratt (MKMP) Algorithm, which is string matching based, and a Modified Principal Component Analysis (MPCA), which is statistics based, are used. DA - 2012 DB - OpenUCT DP - University of Cape Town LK - https://open.uct.ac.za PB - University of Cape Town PY - 2012 T1 - Automated signature generation for Zero-day polymorphic worms using a Double-honeynet TI - Automated signature generation for Zero-day polymorphic worms using a Double-honeynet UR - http://hdl.handle.net/11427/11233 ER - en_ZA
dc.identifier.urihttp://hdl.handle.net/11427/11233
dc.identifier.vancouvercitationMohammed MMZE. Automated signature generation for Zero-day polymorphic worms using a Double-honeynet. [Thesis]. University of Cape Town ,Faculty of Engineering & the Built Environment ,Department of Electrical Engineering, 2012 [cited yyyy month dd]. Available from: http://hdl.handle.net/11427/11233en_ZA
dc.language.isoengen_ZA
dc.publisher.departmentDepartment of Electrical Engineeringen_ZA
dc.publisher.facultyFaculty of Engineering and the Built Environment
dc.publisher.institutionUniversity of Cape Town
dc.subject.otherElectrical Engineeringen_ZA
dc.titleAutomated signature generation for Zero-day polymorphic worms using a Double-honeyneten_ZA
dc.typeDoctoral Thesis
dc.type.qualificationlevelDoctoral
dc.type.qualificationnamePhDen_ZA
uct.type.filetypeText
uct.type.filetypeImage
uct.type.publicationResearchen_ZA
uct.type.resourceThesisen_ZA
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
thesis_ebe_2012_mohammed_m.pdf
Size:
1.23 MB
Format:
Adobe Portable Document Format
Description:
Collections