首页> 外文期刊>IEEE transactions on dependable and secure computing >Theory and Techniques for Automatic Generation of Vulnerability-Based Signatures
【24h】

Theory and Techniques for Automatic Generation of Vulnerability-Based Signatures

机译:自动生成基于漏洞的签名的理论和技术

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we explore the problem of creating emph{vulnerability signatures}. A vulnerability signature is based on a program vulnerability, and is not specific to any particular exploit. The advantage of vulnerability signatures is that their quality can be guaranteed. In particular, we create vulnerability signatures which are guaranteed to have zero false positives. We show how to automate signature creation for any vulnerability that can be detected by a runtime monitor. We provide a formal definition of a vulnerability signature, and investigate the computational complexity of creating and matching vulnerability signatures. We systematically explore the design space of vulnerability signatures. We also provide specific techniques for creating vulnerability signatures in a variety of language classes. In order to demonstrate our techniques, we have built a prototype system. Our experiments show that we can, using a single exploit, automatically generate a vulnerability signature as a regular expression, as a small program, or as a system of constraints. We demonstrate techniques for creating signatures of vulnerabilities which can be exploited via multiple program paths. Our results indicate that our approach is a viable option for signature generation, especially when guarantees are desired.
机译:在本文中,我们探讨了创建emph {漏洞签名}的问题。漏洞签名基于程序漏洞,并不特定于任何特定利用。漏洞签名的优点是可以保证其质量。特别是,我们创建的漏洞签名可以保证零误报。我们展示了如何为运行时监视器可以检测到的任何漏洞自动创建签名。我们提供了漏洞签名的正式定义,并研究了创建和匹配漏洞签名的计算复杂性。我们系统地探索漏洞签名的设计空间。我们还提供了用于在多种语言类中创建漏洞签名的特定技术。为了演示我们的技术,我们建立了一个原型系统。我们的实验表明,我们可以使用一个漏洞利用程序自动将漏洞签名生成为正则表达式,小程序或约束系统。我们演示了创建漏洞签名的技术,这些漏洞可以通过多个程序路径来利用。我们的结果表明,我们的方法是签名生成的可行选择,尤其是在需要保证的情况下。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号