|
[1]R. Sommer and V. Paxson, "Enhancing byte-level network intrusion detection signatures with context," Proceedings of the 10th ACM conference on Computer and communications security, pp. 262-271, 2003. [2]C. Krugel, T. Toth, and E. Kirda, Service specific anomaly detection for network intrusion detection: ACM Press New York, NY, USA, 2002. [3]M. Roesch, "Snort-Lightweight Intrusion Detection for Networks," Proceedings of the 1999 USENIX LISA Systems Administration Conference, 1999. [4]D. M. Kinzle and M. C. Elder, "Internet WORMS: past, present, and future: Recent worms: a survey and trends," Proceedings of the 2003 ACM workshop on Rapid Malcode, ACM, pp. 1-10, 2003. [5]C. C. Zou, L. Gao, W. Gong, and D. Towsley, "Monitoring and early warning for internet worms," Proceedings of the 10th ACM conference on Computer and communication security, pp. 190-199, 2003. [6]D. Moore and C. Shannon, "Code-Red: a case study on the spread and victims of an internet worm," Proceedings of the second ACM SIGCOMM Workshop on Internet measurment, pp. 273-284, 2002. [7]D. Moore, V. Paxson, S. Savage, C. Shannon, S. Staniford, and N. Weaver, "The Spread of the Sapphire/Slammer Worm," IEEE Security and Privacy, July 2003. [8]P. Akritidis, E. P. Markatos, M. Polychronakis, and K. Anagnostakis, "Stride: Polymorphic sled detection through instruction sequence analysis," 20th IFIP International Information Security Conference, 2005. [9]C. Team, "Polymorphic shellcode engine using spectrum analysis," Phrack Magazine, vol. 11, p. 9, 2003. [10]K2, "ADMmutate," http://www.ktwo.ca/ADMmutate-0.8.4.tar.gz. [11]T. Toth and C. Kruegel, "Accurate buffer overflow detection via abstract payload execution," Proceedings of the, vol. 5, pp. 274–291. [12]P. Szor and P. Ferrie, "HUNTING FOR METAMORPHIC," VIRUS, vol. 123, 2001. [13]C. Kaufman, R. Perlman, and M. Speciner, Network security: private communication in a public world: Prentice-Hall, Inc. Upper Saddle River, NJ, USA, 1995. [14]O. Kolesnikov and W. Lee, "Advanced Polymorphic Worms: Evading IDS by Blending in with Normal Traffic," USENIX Security Symposium, 2006. [15]P. Jungck, S. S. Y. Shim, and C. S. Technologies, "Issues in high-speed Internet security," IEEE Computer, vol. 37, pp. 36-42, 2004. [16]M. D. Team, "Metasploit Project, 2006," http://www.metasploit.com/. [17]L. Julus, "Polymorphism Tutorial Part II v1.0 Advanced Approach ", http://vx.netlux.org/lib/static/vdat/tupolyii.htm, 1998. [18]P. Fogla and W. Lee, "Evading network anomaly detection systems: formal reasoning and practical techniques," Proceedings of the 13th ACM conference on Computer and communications security, pp. 59-68, 2006. [19]K. Wang and S. J. Stolfo, "Anomalous Payload-Based Network Intrusion Detection," Recent Advances In Intrusion Detection: 7th International Symposium, RAID 2004, Sophia Antipolis, France, September 15-17, 2004: Proceedings, 2004. [20]J. B. Kruskal Jr, "On the Shortest Spanning Subtree of a Graph and the Traveling Salesman Problem," Proceedings of the American Mathematical Society, vol. 7, pp. 48-50, 1956. [21]K. S. Gatlin, "Windows data alignment on IPF, x86, and x86-64, Feb. 2003. MSDN Library," http://msdn.microsoft.com/. [22]M. Bailey, E. Cooke, F. Jahanian, D. Watson, and J. Nazario, "The Blaster Worm: Then and Now," IEEE SECURITY & PRIVACY, pp. 26-31, 2005. [23]C. A. Ca, "20 W32/Blaster worm," CERT/CC, 2003.
|