首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >SigFree: A Signature-Free Buffer Overflow Attack Blocker
【24h】

SigFree: A Signature-Free Buffer Overflow Attack Blocker

机译:SigFree:无签名缓冲区溢出攻击阻止程序

获取原文
获取原文并翻译 | 示例

摘要

We propose SigFree, an online signature-free out-of-the-box application-layer method for blocking code-injection buffer overflow attack messages targeting at various Internet services such as Web service. Motivated by the observation that buffer overflow attacks typically contain executables whereas legitimate client requests never contain executables in most Internet services, SigFree blocks attacks by detecting the presence of code. Unlike the previous code detection algorithms, SigFree uses a new data-flow analysis technique called code abstraction that is generic, fast, and hard for exploit code to evade. SigFree is signature free, thus it can block new and unknown buffer overflow attacks; SigFree is also immunized from most attack-side code obfuscation methods. Since SigFree is a transparent deployment to the servers being protected, it is good for economical Internet-wide deployment with very low deployment and maintenance cost. We implemented and tested SigFree; our experimental study shows that the dependency-degree-based SigFree could block all types of code-injection attack packets (above 750) tested in our experiments with very few false positives. Moreover, SigFree causes very small extra latency to normal client requests when some requests contain exploit code.
机译:我们提出了SigFree,这是一种在线的,无现成的在线应用程序即用层方法,用于阻止针对各种Internet服务(例如Web服务)的代码注入缓冲区溢出攻击消息。由于观察到缓冲区溢出攻击通常包含可执行文件,而合法的客户端请求在大多数Internet服务中却从未包含可执行文件,因此SigFree通过检测代码的存在来阻止攻击。与以前的代码检测算法不同,SigFree使用一种称为代码抽象的新数据流分析技术,该技术通用,快速且难以逃避利用代码。 SigFree没有签名,因此可以阻止新的和未知的缓冲区溢出攻击。 SigFree还免于大多数攻击方代码混淆方法的攻击。由于SigFree是对受保护服务器的透明部署,因此对于经济型Internet范围内的部署非常有利,并且部署和维护成本非常低。我们实施并测试了SigFree;我们的实验研究表明,基于依赖度的SigFree可以阻止在我们的实验中测试的所有类型的代码注入攻击数据包(750以上),且误报率极低。此外,当某些请求包含漏洞利用代码时,SigFree对普通客户端请求会产生很小的额外延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号