首页> 外文会议> >Polygraph: automatically generating signatures for polymorphic worms
【24h】

Polygraph: automatically generating signatures for polymorphic worms

机译:测谎仪:自动为多态蠕虫生成签名

获取原文
获取外文期刊封面目录资料

摘要

It is widely believed that content-signature-based intrusion detection systems (IDS) are easily evaded by polymorphic worms, which vary their payload on every infection attempt. In this paper, we present Polygraph, a signature generation system that successfully produces signatures that match polymorphic worms. Polygraph generates signatures that consist of multiple disjoint content substrings. In doing so, Polygraph leverages our insight that for a real-world exploit to function properly, multiple invariant substrings must often be present in all variants of a payload; these substrings typically correspond to protocol framing, return addresses, and in some cases, poorly obfuscated code. We contribute a definition of the polymorphic signature generation problem; propose classes of signature suited for matching polymorphic worm payloads; and present algorithms for automatic generation of signatures in these classes. Our evaluation of these algorithms on a range of polymorphic worms demonstrates that Polygraph produces signatures for polymorphic worms that exhibit low false negatives and false positives.
机译:人们普遍认为,基于内容签名的入侵检测系统(IDS)容易被多态蠕虫规避,这种蠕虫会在每次感染尝试时改变其有效负载。在本文中,我们介绍了Polygraph,这是一个签名生成系统,可以成功生成与多态蠕虫匹配的签名。测谎仪生成的签名由多个不相交的内容子字符串组成。通过这样做,Polygraph利用了我们的见识,即为了使真实世界的漏洞利用正常工作,有效载荷的所有变体中通常必须存在多个不变的子字符串。这些子字符串通常对应于协议框架,返回地址,并且在某些情况下还包含混淆不清的代码。我们为多态签名生成问题做出了定义;提出适合于匹配多态蠕虫有效载荷的签名类别;并提出了用于在这些类中自动生成签名的算法。我们对一系列多态蠕虫的这些算法的评估表明,Polygraph为表现出低假阴性和假阳性的多态蠕虫产生了签名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号