首页> 外文会议> >ShieldGen: Automatic Data Patch Generation for Unknown Vulnerabilities with Informed Probing
【24h】

ShieldGen: Automatic Data Patch Generation for Unknown Vulnerabilities with Informed Probing

机译:ShieldGen:使用已知探测自动生成未知漏洞的数据补丁

获取原文

摘要

In this paper, we present ShieldGen, a system for automatically generating a data patch or a vulnerability signature for an unknown vulnerability, given a zero-day attack instance. The key novelty in our work is that we leverage knowledge of the data format to generate new potential attack instances, which we call probes, and use a zero-day detector as an oracle to determine if an instance can still exploit the vulnerability; the feedback of the oracle guides our search for the vulnerability signature. We have implemented a ShieldGen prototype and experimented with three known vulnerabilities. The generated signatures have no false positives and a low rate of false negatives due to imperfect data format specifications and the sampling technique used in our probe generation. Overall, they are significantly more precise than the signatures generated by existing schemes. We have also conducted a detailed study of 25 vulnerabilities for which Microsoft has issued security bulletins between 2003 and 2006. We estimate that ShieldGen can produce high quality signatures for a large portion of those vulnerabilities and that the signatures are superior to the signatures generated by existing schemes.
机译:在本文中,我们介绍了ShieldGen,这是一个针对零日攻击实例自动为未知漏洞生成数据补丁或漏洞签名的系统。我们工作中的关键新颖之处在于,我们利用数据格式的知识来生成新的潜在攻击实例(称为探针),并使用零日检测器作为预言机来确定实例是否仍然可以利用该漏洞; oracle的反馈指导我们搜索漏洞签名。我们已经实现了ShieldGen原型,并尝试了三个已知漏洞。由于数据格式规范和探针生成中使用的采样技术不完善,因此生成的签名没有误报,误报率也很低。总体而言,它们比现有方案生成的签名精确得多。我们还对Microsoft在2003年至2006年间发布的25个漏洞进行了详细研究。我们估计ShieldGen可以为其中的大部分漏洞生成高质量的签名,并且这些签名要优于现有漏洞所生成的签名。计划。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号