首页> 外文会议>Network and Distributed System Security Symposium >Protocol-Independent Adaptive Replay of Application Dialog
【24h】

Protocol-Independent Adaptive Replay of Application Dialog

机译:协议无关的应用程序对话的自适应重放

获取原文

摘要

For many applications--including recognizing malware variants, determining the range of system versions vulnerable to a given attack, testing defense mechanisms, and filtering multi-step attacks--it can be highly useful to mimic an existing system while interacting with a live host on the network. We present RolePlayer, a system which, given examples of an application session, can mimic both the client side and the server side of the session for a wide variety of application protocols. A key property of RolePlayer is that it operates in an application-independent fashion: the system does not require any specifics about the particular application it mimics. It instead uses byte-stream alignment algorithms to compare different instances of a session to determine which fields it must change to successfully replay one side of the session. Drawing only on knowledge of a few low-level syntactic conventions (such as representing IP addresses using "dotted quads"), and contextual information such as the domain names of the participating hosts, RolePlayer can heuristically detect and adjust network addresses, ports, cookies, and length fields embedded within the session, including sessions that span multiple, concurrent connections on dynamically assigned ports. We have successfully used RolePlayer to replay both the client and server sides for a variety of network applications, including NFS, FTP, and CIFS/SMB file transfers, as well as the multi-stage infection processes of the Blaster and W32.Randex.D worms.
机译:对于许多应用程序 - 包括识别恶意软件变体,确定容易受到给定攻击,测试防御机制和过滤多步攻击的系统版本的范围 - 模拟现有系统在与实时主机交互时,它可能非常有用在网络上。我们存在Logplayer,一个系统,该系统,其给出应用程序会话的示例,可以模拟客户端和会话的服务器端,以获得各种应用协议。角色扮演者的一个关键属性是它以自主应用程序运行:系统不需要对其模拟的特定应用程序的任何细节。它改为使用字节流对齐算法来比较会话的不同实例,以确定它必须改变的字段成功重播会话的一侧。仅绘制几个低级句法约定的知识(例如使用“点缀四边形”)和参与主机的域名等IP地址,角色扮演者可以启发式检测和调整网络地址,端口,Cookie嵌入在会话中的长度字段,包括在动态分配的端口上跨越多个并发连接的会话。我们已经成功使用了角色扮演者来重放客户端和服务器边的各种网络应用程序,包括NFS,FTP和CIFS / SMB文件转移,以及Blaster和W32.randex.d的多级感染过程蠕虫。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号