1 research outputs found
Advanced Trace Pattern For Computer Intrusion Discovery
The number of crime committed based on the malware intrusion is never ending
as the number of malware variants is growing tremendously and the usage of
internet is expanding globally. Malicious codes easily obtained and use as one
of weapon to gain their objective illegally. Hence, in this research, diverse
logs from different OSI layer are explored to identify the traces left on the
attacker and victim logs in order to establish worm trace pattern to defending
against the attack and help revealing true attacker or victim. For the purpose
of this paper, it focused on malware intrusion and traditional worm namely
sasser worm variants. The concept of trace pattern is created by fusing the
attacker's and victim's perspective. Therefore, the objective of this paper is
to propose a general worm trace pattern for attacker's, victim's and multi-step
(attacker/victim)'s by combining both perspectives. These three proposed worm
trace patterns can be extended into research areas in alert correlation and
computer forensic investigation.Comment: IEEE Publication Format,
https://sites.google.com/site/journalofcomputing