首页> 外文期刊>Networking, IEEE/ACM Transactions on >Thwarting Zero-Day Polymorphic Worms With Network-Level Length-Based Signature Generation
【24h】

Thwarting Zero-Day Polymorphic Worms With Network-Level Length-Based Signature Generation

机译:使用基于网络级别的基于长度的签名生成来阻止零日多态蠕虫

获取原文
       

摘要

It is crucial to detect zero-day polymorphic worms and to generate signatures at network gateways or honeynets so that we can prevent worms from propagating at their early phase. However, most existing network-based signatures are specific to exploit and can be easily evaded. In this paper, we propose generating vulnerability-driven signatures at network level without any host-level analysis of worm execution or vulnerable programs. As the first step, we design a network-based length-based signature generator (LESG) for the worms exploiting buffer overflow vulnerabilities. The signatures generated are intrinsic to buffer overflows, and are very difficult for attackers to evade. We further prove the attack resilience bounds even under worst-case attacks with deliberate noise injection. Moreover, LESG is fast and noise-tolerant and has efficient signature matching. Evaluation based on real-world vulnerabilities of various protocols and real network traffic demonstrates that LESG is promising in achieving these goals.
机译:检测零日多态蠕虫并在网络网关或蜜网中生成签名非常重要,这样我们才能防止蠕虫在其早期传播。但是,大多数现有的基于网络的签名都是特定于要利用的,并且很容易逃避。在本文中,我们建议在网络级别生成漏洞驱动的签名,而无需对蠕虫执行或易受攻击的程序进行任何主机级别的分析。第一步,我们为蠕虫利用缓冲区溢出漏洞设计一个基于网络的基于长度的签名生成器(LESG)。生成的签名是缓冲区溢出所固有的,并且攻击者很难逃避。我们进一步证明了即使在最坏情况下通过故意注入噪声的情况下,攻击的恢复能力也达到了极限。此外,LESG快速且耐噪声,并且具有有效的签名匹配。根据各种协议的实际漏洞和实际网络流量进行的评估表明,LESG在实现这些目标方面很有前途。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号