TY - GEN
T1 - SpyCon
T2 - 27th IEEE International Performance Computing and Communications Conference, IPCCC 07
AU - Chandrasekaran, M.
AU - Vidyaraman, S.
AU - Upadhyaya, S.
PY - 2007
Y1 - 2007
N2 - The success of any spyware is determined by its ability to evade detection. Although traditional detection methodologies employing signature and anomaly based systems have had reasonable success, new class of spyware programs emerge which blend in with user activities to avoid detection. One of the latest antispyware technologies consists of a local agent that generates honeytokens of known parameters (e.g., network access requests) and tricks spyware into assuming it to be legitimate activity. In this paper, as a first step, we address the deficiencies of static honeytoken generation and present an attack that circumvents such detection techniques. We synthesize the attack by means of data mining algorithms like associative rule mining. Next, we present a randomized honeytoken generation mechanism to address this new class of spyware. Experimental results show that (i) static honeytokens are detected with near 100% accuracy, thereby defeating the state-of-the-art anti-spyware technique, (ii) randomized honeytoken generation mechanism is an effective anti-spyware solution.
AB - The success of any spyware is determined by its ability to evade detection. Although traditional detection methodologies employing signature and anomaly based systems have had reasonable success, new class of spyware programs emerge which blend in with user activities to avoid detection. One of the latest antispyware technologies consists of a local agent that generates honeytokens of known parameters (e.g., network access requests) and tricks spyware into assuming it to be legitimate activity. In this paper, as a first step, we address the deficiencies of static honeytoken generation and present an attack that circumvents such detection techniques. We synthesize the attack by means of data mining algorithms like associative rule mining. Next, we present a randomized honeytoken generation mechanism to address this new class of spyware. Experimental results show that (i) static honeytokens are detected with near 100% accuracy, thereby defeating the state-of-the-art anti-spyware technique, (ii) randomized honeytoken generation mechanism is an effective anti-spyware solution.
KW - Associative rule mining
KW - Honeytokens
KW - Spyware
KW - User activity
UR - https://www.scopus.com/pages/publications/36348953682
U2 - 10.1109/PCCC.2007.358933
DO - 10.1109/PCCC.2007.358933
M3 - Conference contribution
AN - SCOPUS:36348953682
SN - 1424411386
SN - 9781424411382
T3 - Conference Proceedings of the IEEE International Performance, Computing, and Communications Conference
SP - 502
EP - 509
BT - 27th IEEE International Performance Computing and Communications Conference, IPCCC 07
Y2 - 11 April 2007 through 13 April 2007
ER -