TY - JOUR
T1 - Auto-Sign
T2 - An automatic signature generator for high-speed malware filtering devices
AU - Tahan, Gil
AU - Glezer, Chanan
AU - Elovici, Yuval
AU - Rokach, Lior
N1 - Funding Information:
This work has been supported by Deutsche Telekom AG.
PY - 2010
Y1 - 2010
N2 - This research proposes a novel automatic method (termed Auto-Sign) for extracting unique signatures of malware executables to be used by high-speed malware filtering devices based on deep-packet inspection and operating in real-time. Contrary to extant string and token-based signature generation methods, we implemented Auto-Sign an automatic signature generation method that can be used on large-size malware by disregarding signature candidates which appear in benign executables. Results from experimental evaluation of the proposed method suggest that picking a collection of executables which closely represents commonly used code, plays a key role in achieving highly specific signatures which yield low false positives.
AB - This research proposes a novel automatic method (termed Auto-Sign) for extracting unique signatures of malware executables to be used by high-speed malware filtering devices based on deep-packet inspection and operating in real-time. Contrary to extant string and token-based signature generation methods, we implemented Auto-Sign an automatic signature generation method that can be used on large-size malware by disregarding signature candidates which appear in benign executables. Results from experimental evaluation of the proposed method suggest that picking a collection of executables which closely represents commonly used code, plays a key role in achieving highly specific signatures which yield low false positives.
UR - http://www.scopus.com/inward/record.url?scp=77955090968&partnerID=8YFLogxK
U2 - 10.1007/s11416-009-0119-3
DO - 10.1007/s11416-009-0119-3
M3 - ???researchoutput.researchoutputtypes.contributiontojournal.article???
AN - SCOPUS:77955090968
SN - 1772-9890
VL - 6
SP - 91
EP - 103
JO - Journal in Computer Virology
JF - Journal in Computer Virology
IS - 2
ER -