首页> 外文会议>ICT systems security and privacy protection >Ghost Patches: Fake Patches for Fake Vulnerabilities
【24h】

Ghost Patches: Fake Patches for Fake Vulnerabilities

机译:幽灵补丁:虚假补丁

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Offensive and defensive players in the cyber security sphere constantly react to either party's actions. This reactive approach works well for attackers but can be devastating for defenders. This approach also models the software security patching lifecycle. Patches fix security flaws, but when deployed, can be used to develop malicious exploits. To make exploit generation using patches more resource intensive, we propose inserting deception into software security patches. These ghost patches mislead attackers with deception and fix legitimate flaws in code. An adversary using ghost patches to develop exploits will be forced to use additional resources. We implement a proof of concept for ghost patches and evaluate their impact on program analysis and runtime. We find that these patches have a statistically significant impact on dynamic analysis runtime, increasing time to analyze by a factor of up to 14a;, but do not have a statistically significant impact on program runtime.
机译:网络安全领域的进攻性和防御性参与者不断对任何一方的行为做出反应。这种反应性方法对于攻击者而言效果很好,但对防御者而言却是毁灭性的。这种方法还可以对软件安全补丁生命周期进行建模。补丁可修复安全漏洞,但在部署时可用于开发恶意攻击。为了使使用补丁的漏洞利用生成更加占用资源,我们建议在软件安全补丁中插入欺骗手段。这些虚假补丁会欺骗欺骗者,并修复代码中的合法缺陷。使用虚假补丁开发攻击程序的对手将被迫使用其他资源。我们为鬼补丁实施了概念验证,并评估了它们对程序分析和运行时的影响。我们发现这些补丁对动态分析运行时间具有统计上的显着影响,将分析时间增加了多达14a;但是对程序运行时没有统计上的显着影响。

著录项

  • 来源
  • 会议地点 Rome(IT)
  • 作者单位

    Computer Science Department and CERIAS, Purdue University, 305 N. University St., West Lafayette, IN 47907, USA;

    Computer Science Department and CERIAS, Purdue University, 305 N. University St., West Lafayette, IN 47907, USA;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号