首页> 外文OA文献 >Polygraph: Automatically Generating Signatures for Polymorphic Worms
【2h】

Polygraph: Automatically Generating Signatures for Polymorphic Worms

机译:测谎仪:自动生成多态蠕虫的签名

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

It is widely believed that content-signature-based intrusion detection systems (IDS) are easily evaded by polymorphic worms, which vary their payload on every infection attempt. In this paper, we present Polygraph, a signature generation system that successfully produces signatures that match polymorphic worms. Polygraph generates signatures that consist of multiple disjoint content substrings. In doing so, Polygraph leverages our insight that for a real-world exploit to function properly, multiple invariant substrings must often be present in all variants of a payload; these substrings typically correspond to protocol framing, return addresses, and in some cases, poorly obfuscated code. We contribute a definition of the polymorphic signature generation problem; propose classes of signature suited for matching polymorphic worm payloads; and present algorithms for automatic generation of signatures in these classes. Our evaluation of these algorithms on a range of polymorphic worms demonstrates that Polygraph produces signatures for polymorphic worms that exhibit low false negatives and false positives.
机译:人们普遍认为,基于内容签名的入侵检测系统(IDS)容易被多态蠕虫规避,这种蠕虫会在每次感染尝试中改变其有效负载。在本文中,我们介绍了Polygraph,这是一个签名生成系统,可以成功生成与多态蠕虫匹配的签名。测谎仪生成的签名由多个不相交的内容子字符串组成。通过这样做,Polygraph利用了我们的见识,即为了使现实世界中的攻击正常工作,有效载荷的所有变体中通常必须存在多个不变的子字符串。这些子字符串通常对应于协议框架,返回地址,并且在某些情况下还包含混淆不清的代码。我们为多态签名生成问题做出了定义;提出适合于匹配多态蠕虫有效载荷的签名类别;并提出了用于在这些类中自动生成签名的算法。我们对一系列多态蠕虫的这些算法的评估表明,Polygraph为表现出低假阴性和假阳性的多态蠕虫产生了签名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号