【24h】

Shield

机译:

获取原文

摘要

Software patching has not been effective as a first-line defense against large-scale worm attacks, even when patches have long been available for their corresponding vulnerabilities. Generally, people have been reluctant to patch their systems immediately, because patches are perceived to be unreliable and disruptive to apply. To address this problem, we propose a first-line worm defense in the network stack, using shields -- vulnerability-specific, exploit-generic network filters installed in end systems once a vulnerability is discovered, but before a patch is applied. These filters examine the incoming or outgoing traffic of vulnerable applications, and correct traffic that exploits vulnerabilities. Shields are less disruptive to install and uninstall, easier to test for bad side effects, and hence more reliable than traditional software patches. Further, shields are resilient to polymorphic or metamorphic variations of exploits [43].In this paper, we show that this concept is feasible by describing a prototype Shield framework implementation that filters traffic above the transport layer. We have designed a safe and restrictive language to describe vulnerabilities as partial state machines of the vulnerable application. The expressiveness of the language has been verified by encoding the signatures of several known vulnerabilites. Our evaluation provides evidence of Shield's low false positive rate and small impact on application throughput. An examination of a sample set of known vulnerabilities suggests that Shield could be used to prevent exploitation of a substantial fraction of the most dangerous ones.
机译:即使在适用于其相应漏洞的补丁,软件修补也没有作为针对大规模蠕虫攻击的一线防御。一般来说,人们一直不愿立即修补他们的系统,因为斑块被认为是不可靠和持久的贴补。为了解决这个问题,我们在网络堆栈中提出了一线蠕虫防御,使用盾牌 - 一旦发现漏洞,在终端系统中安装的漏洞特定于漏洞的泛型网络过滤器,但之前应用补丁。这些过滤器检查易受攻击应用程序的传入或传出流量,以及利用漏洞的正确流量。屏蔽不太易于安装和卸载,更容易测试不良副作用,因此比传统软件补丁更可靠。此外,屏蔽是有弹性的多态性或变质变化的弹性[43]。在本文中,我们表明该概念是可行的,通过描述筛选在传输层上方的流量的原型屏蔽框架实现是可行的。我们设计了一种安全和限制的语言,可以将漏洞描述为易受攻击应用程序的部分状态机。通过编码若干已知的漏洞的签名来验证语言的表达力。我们的评价提供了盾牌低误率和对应用吞吐量的小的影响。对一组已知漏洞的检查表明,屏蔽可用于防止利用大部分最危险的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号