...
首页> 外文期刊>Procedia Computer Science >SecondDEP: Resilient Computing that Prevents Shellcode Execution in Cyber-Attacks
【24h】

SecondDEP: Resilient Computing that Prevents Shellcode Execution in Cyber-Attacks

机译:SecondDEP:弹性计算,可防止网络攻击中的Shellcode执行

获取原文
   

获取外文期刊封面封底 >>

       

摘要

This paper proposes a novel method of preventing shellcode execution even if DEP is bypassed. The method prevents Windows APIs from calling on a data area by API hooking, based on evidence that shellcode is executed in a data area and that the shellcode calls Windows APIs. Performance tests indicated that all samples of shellcode provided by Metasploit Framework, as well asthe 18 most recent attacks using Metasploit Framework, can be detected. Comparison of this method with anti-virus products showed that this method prevented shellcode execution, whereas anti-virus products failed. Another test showed that the overhead of the method has little effect on the performance of computer operations.
机译:本文提出了一种即使在绕过DEP的情况下也可以防止shellcode执行的新颖方法。该方法基于外壳程序代码在数据区域中执行且外壳程序代码调用Windows API的证据,从而防止Windows API通过API挂钩来调用数据区域。性能测试表明,可以检测到Metasploit框架提供的所有shellcode示例以及使用Metasploit框架的18种最新攻击。此方法与防病毒产品的比较表明,此方法阻止了Shellcode的执行,而防病毒产品却失败了。另一个测试表明,该方法的开销对计算机操作的性能影响很小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号