NetSpy : Automatic Generation of Spyware Signatures for NIDS
File Size:
KB
Developer:
Description:
We present NetSpy, a tool to automatically generate network-level signatures for spyware. NetSpy determines whether an untrusted program is spyware by correlating user input with network traffic generated by the untrusted program. If classified as spyware, NetSpy also generates a signature characterizing the malicious substrate of the spy-wares network behavior. Such a signature can be used by network intrusion detection systems to detect spyware installations in large networks.