首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >Online Signature Generation for Windows Systems
【24h】

Online Signature Generation for Windows Systems

机译:Windows系统的在线签名生成

获取原文

摘要

In this paper, we present a new, light-weight approach for generating filters for blocking buffer overflow attacks on Microsoft Windows systems. It is designed to be deployable as an "always on'' component on production systems. To achieve this goal, it avoids expensive and intrusive techniques such as taint-tracking. The online nature of our system enables it to provide protection from a range of memory corruption exploits, including those involving unknown vulnerabilities, or known vulnerabilities but unknown exploits. In contrast, most previous signature generation techniques need to be run in sandboxed environments, and need working exploits to generate signatures. Moreover, our technique overcomes the "gap'' problem faced by previous signature generation mechanisms, i.e., when the vulnerable memory region is corrupted between the overflow and the time an attack is detected. Another novel feature of our approach is that it is able to reason about likely lengths of vulnerable buffers, which can lead to more accurate signatures. Our experimental results are very promising, and demonstrate that the approach can generate effective signatures for many synthetic and real-world vulnerabilities.
机译:在本文中,我们提出了一种新的轻量级方法,用于生成用于阻止Microsoft Windows系统上的缓冲区溢出攻击的过滤器。它被设计为可作为生产系统上的“始终在线”组件进行部署。为实现此目标,它避免了诸如污迹追踪之类的昂贵且侵入性的技术。内存破坏漏洞利用,包括那些涉及未知漏洞或已知漏洞但漏洞利用的漏洞,相比之下,大多数以前的签名生成技术都需要在沙盒环境中运行,并且需要有效的漏洞利用才能生成签名,而且,我们的技术还克服了“漏洞”先前的签名生成机制所面临的问题,即当易受攻击的存储区域在溢出和检测到攻击的时间之间被破坏时。我们方法的另一个新颖之处在于,它能够推断出易受攻击的缓冲区的可能长度,这可能导致更准确的签名。我们的实验结果非常有前途,并证明该方法可以为许多综合和现实漏洞生成有效的签名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号