Detecting scanning computer worms using machine learning and darkspace network traffic

dc.contributor.authorOchieng, Nelson
dc.contributor.authorIsmail, Ateya
dc.contributor.authorWaweru, Mwangi
dc.contributor.authorOrero, Joseph
dc.date.accessioned2017-07-21T12:29:15Z
dc.date.available2017-07-21T12:29:15Z
dc.date.issued2017
dc.descriptionThe conference aimed at supporting and stimulating active productive research set to strengthen the technical foundations of engineers and scientists in the continent, through developing strong technical foundations and skills, leading to new small to medium enterprises within the African sub-continent. It also seeked to encourage the emergence of functionally skilled technocrats within the continent.en_US
dc.description.abstractThe subject of this paper is computer worm detection in a network. Computers worms have been defined as a process that can cause a possibly evolved copy of it to execute on a remote computer. They do not require human intervention to propagate; neither do they need to attach themselves to existing files. Computer worms spread very rapidly and modern worm authors obfuscate their code to make it difficult to detect them. This paper proposes to use machine learning to detect them. The paper deviates from existing approaches in that it uses the darkspace network traffic attributed to an actual worm attack to validate the algorithms. In addition, it attempts to understand the threat model, the feature set and the detection algorithms to explain the best combination of features and why the best algorithms succeeds where others have failed.en_US
dc.description.sponsorshipStrathmore University; Institute of Electrical and Electronics Engineers (IEEE)en_US
dc.identifier.citationOchieng, N., Ateya, I., Waweru, M., & Orero, J. (2017). Detecting scanning computer worms using machine learning and darkspace network traffic. In Pan African Conference on Science, Computing and Telecommunications (PACT). Nairobi: Strathmore University. Retrieved from https://su-plus.strathmore.eduen_US
dc.identifier.urihttp://hdl.handle.net/11071/5182
dc.language.isoenen_US
dc.publisherStrathmore Universityen_US
dc.subjectComputer worm detectionen_US
dc.subjectMalware detectionen_US
dc.subjectMachine learningen_US
dc.subjectDarkspace network trafficen_US
dc.subjectbehavioral computer worm detectionen_US
dc.titleDetecting scanning computer worms using machine learning and darkspace network trafficen_US
dc.typeConference Paperen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Detecting Scanning Computer Worms Using Machine.pdf
Size:
257.55 KB
Format:
Adobe Portable Document Format
Description:
Full text
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: