<?xml version="1.0" encoding="UTF-8"?>
<doi_batch version="5.3.1" xmlns="http://www.crossref.org/schema/5.3.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:jats="http://www.ncbi.nlm.nih.gov/JATS1" xmlns:ai="http://www.crossref.org/AccessIndicators.xsd" xsi:schemaLocation="http://www.crossref.org/schema/5.3.1 http://www.crossref.org/schema/deposit/crossref5.3.1.xsd">
 <head>
  <doi_batch_id>aspg-2-3070-1791419362</doi_batch_id>
  <timestamp>20261008002922</timestamp>
  <depositor>
   <depositor_name>American Scientific Publishing Group</depositor_name>
   <email_address>admin@americaspg.com</email_address>
  </depositor>
  <registrant>American Scientific Publishing Group</registrant>
 </head>
 <body>
  <journal>
   <journal_metadata language="en">
    <full_title>Journal of Cybersecurity and Information Management</full_title>
    <abbrev_title>JCIM</abbrev_title>
    <issn media_type="print">2769-7851</issn>
    <issn media_type="electronic">2690-6775</issn>
   </journal_metadata>
   <journal_issue>
    <publication_date media_type="online">
     <year>2025</year>
    </publication_date>
    <journal_volume>
     <volume>15</volume>
    </journal_volume>
    <issue>1</issue>
   </journal_issue>
   <journal_article publication_type="full_text">
    <titles>
     <title>Detecting Zero-day Polymorphic Worms Using Honeywall</title>
    </titles>
    <contributors>
     <person_name sequence="first" contributor_role="author">
      <given_name>Mohssen</given_name>
      <surname>Mohammed</surname>
      <affiliations>
       <institution>
        <institution_name>College of Computing and Informatics, University of Sharjah, UAE</institution_name>
       </institution>
      </affiliations>
     </person_name>
     <person_name sequence="additional" contributor_role="author">
      <given_name>Mohamed Abdalla</given_name>
      <surname>Nour</surname>
      <affiliations>
       <institution>
        <institution_name>College of Computing and Informatics, University of Sharjah, UAE</institution_name>
       </institution>
      </affiliations>
     </person_name>
     <person_name sequence="additional" contributor_role="author">
      <given_name>Mohamed</given_name>
      <surname>Elhoseny</surname>
      <affiliations>
       <institution>
        <institution_name>College of Computing and Informatics, University of Sharjah, UAE</institution_name>
       </institution>
      </affiliations>
     </person_name>
    </contributors>
    <jats:abstract>
     <jats:p>A polymorphic worm is a kind of worm that can change its payload in every infection attempt, so it can evade the Intrusion Detection Systems (IDSs) and perform illegal activities that lead to high losses. These worms can mutate as they spread across the network, causing most of the existing IDSs to carry out the polymorphic worm’s detection with high levels of both false positives and false negatives. In this paper, we propose a double-honeynet system that can detect polymorphic worm instances automatically. The Double-honeynet system is a hybrid system with both Network-based and Host-based mechanisms. This allows us to collect polymorphic worm instances at the network-level and host-level, which reduces the false positives and false negatives dramatically. The experimental deployment of a Double-honeynet network over a seven-day period successfully collected instances of various polymorphic worms, including 3511 Allaple, 3228 Conficker, 2817 Blaster, and 2452 Sasser worms. By utilizing, the Honeywall's Walleye interface; we were able to analyze the data and simulate the detection of these worms by generating new signatures, which were not previously recorded, demonstrating the system's capability to detect zero-day polymorphic threats. Analysis of Blaster worm instances revealed significant similarities in their payloads due to exe headers, indicating the necessity of preprocessing to remove these headers before signature generation, although the generation of signatures is beyond the scope of this study.</jats:p>
    </jats:abstract>
    <publication_date media_type="online">
     <year>2025</year>
    </publication_date>
    <pages>
     <first_page>34</first_page>
     <last_page>49</last_page>
    </pages>
    <publisher_item>
     <item_number item_number_type="article-number">3070</item_number>
    </publisher_item>
    <ai:program name="AccessIndicators">
     <ai:license_ref applies_to="vor">https://creativecommons.org/licenses/by/4.0/</ai:license_ref>
    </ai:program>
    <doi_data>
     <doi>10.54216/JCIM.150104</doi>
     <resource>https://www.americaspg.com/journal/2/article/3070</resource>
     <collection property="text-mining">
      <item>
       <resource mime_type="application/pdf">https://www.americaspg.com/storage/31721429374.pdf</resource>
      </item>
     </collection>
    </doi_data>
   </journal_article>
  </journal>
 </body>
</doi_batch>
