Automatic Defense Against Zero-day Polymorphic Worms in Communication Networks (Hardcover)
暫譯: 通訊網路中對零日多形蟲的自動防禦 (精裝版)

Mohssen Mohammed, Al-Sakib Khan Pathan

買這商品的人也買了...

相關主題

商品描述

Able to propagate quickly and change their payload with each infection, polymorphic worms have been able to evade even the most advanced intrusion detection systems (IDS). And, because zero-day worms require only seconds to launch flooding attacks on your servers, using traditional methods such as manually creating and storing signatures to defend against these threats is just too slow.

Bringing together critical knowledge and research on the subject, Automatic Defense Against Zero-day Polymorphic Worms in Communication Networks details a new approach for generating automated signatures for unknown polymorphic worms. It presents experimental results on a new method for polymorphic worm detection and examines experimental implementation of signature-generation algorithms and double-honeynet systems.

If you need some background, the book includes an overview of the fundamental terms and concepts in network security, including the various security models. Clearing up the misconceptions about the value of honeypots, it explains how they can be useful in securing your networks, and identifies open-source tools you can use to create your own honeypot. There’s also a chapter with references to helpful reading resources on automated signature generation systems.

The authors describe cutting-edge attack detection approaches and detail new algorithms to help you generate your own automated signatures for polymorphic worms. Explaining how to test the quality of your generated signatures, the text will help you develop the understanding required to effectively protect your communication networks. Coverage includes intrusion detection and prevention systems (IDPS), zero-day polymorphic worm collection methods, double-honeynet system configurations, and the implementation of double-honeynet architectures.

商品描述(中文翻譯)

能夠快速傳播並在每次感染時改變其有效載荷的多形態蠕蟲,已能夠避開即使是最先進的入侵檢測系統 (IDS)。而且,由於零日蠕蟲只需幾秒鐘就能對您的伺服器發起洪水攻擊,使用傳統方法,例如手動創建和存儲簽名來防禦這些威脅,實在是太慢了。

《自動防禦通信網路中的零日多形態蠕蟲》匯集了關於該主題的關鍵知識和研究,詳細介紹了一種為未知多形態蠕蟲生成自動簽名的新方法。它呈現了多形態蠕蟲檢測的新方法的實驗結果,並檢查了簽名生成算法和雙蜜罐系統的實驗實施。

如果您需要一些背景知識,本書包括網路安全的基本術語和概念的概述,包括各種安全模型。澄清了關於蜜罐價值的誤解,解釋了它們如何在保護您的網路中發揮作用,並識別了您可以用來創建自己蜜罐的開源工具。還有一章提到有關自動簽名生成系統的有用閱讀資源。

作者描述了尖端的攻擊檢測方法,並詳細介紹了幫助您為多形態蠕蟲生成自動簽名的新算法。解釋了如何測試您生成的簽名的質量,文本將幫助您發展有效保護通信網路所需的理解。內容包括入侵檢測和預防系統 (IDPS)、零日多形態蠕蟲收集方法、雙蜜罐系統配置以及雙蜜罐架構的實施。