Synthesizing Fast Intrusion Prevention/Detection Systems from High-Level Specifications

Synthesizing Fast Intrusion Prevention/Detection Systems from High-Level Specifications
复制标题

根据高级规范综合快速入侵防御/检测系统

DOI:
--
复制
发表时间:
1999
期刊:
--
影响因子:
--
通讯作者:
Prem Uppuluri
Prem Uppuluri
中科院分区:
--
文献类型:
--
作者:
R. Sekar;Prem Uppuluri

文献摘要

被引文献

相似文献

构建可生存的信息系统(即,尽管存在协同攻击,但仍继续提供服务的系统),因此有必要在入侵影响系统性能或功能之前检测并隔离入侵。这一领域以前的研究主要集中在事后检测入侵,而不是首先防止它们。我们已经开发出一种新的方法,基于指定预期的程序行为,使用模式序列的系统调用。这些模式还可以捕获系统调用参数值的条件。在运行时,我们拦截进程发出的系统调用,将它们与规范进行比较,并禁止(或以其他方式修改)那些偏离规范的调用。由于我们的方法是能够修改系统调用之前,它被传递到操作系统内核,它是能够作出反应之前,任何造成损害的系统调用被攻击下的进程执行。我们提出我们的规范语言,并说明其使用开发的ftp服务器的规范。注意,在我们的方法中,每个系统调用都被拦截,并受到潜在的昂贵操作的影响,以便与指定正常/异常行为的许多模式进行匹配。因此,最大限度地减少模式匹配所产生的开销是我们的方法的可行性的关键。我们解决这个问题,开发一个新的,低开销的算法匹配运行时的行为对规范。我们的算法的一个显着特点是,它的运行时间几乎是独立的模式的数量。在大多数情况下,它对每个被截获的系统调用使用固定的时间量,并使用固定的存储量,这两种情况都与模式的大小或数量无关。这些好处使我们的算法有用的许多其他入侵检测方法,采用模式匹配。我们描述了我们的算法,并通过实验评估其性能。
To build survivable information systems (i.e., systems that continue to provide their services in spite of coordinated attacks), it is necessary to detect and isolate intrusions before they impact system performance or functionality. Previous research in this area has focussed primarily on detecting intrusions after the fact, rather than preventing them in the first place. We have developed a new approach based on specifying intended program behaviors using patterns over sequences of system calls. The patterns can also capture conditions on the values of system-call arguments. At runtime, we intercept the system calls made by processes, compare them against specifications, and disallow (or otherwise modify) those calls that deviate from specifications. Since our approach is capable of modifying a system call before it is delivered to the operating system kernel, it is capable of reacting before any damage-causing system call is executed by a process under attack. We present our specification language and illustrate its use by developing a specification for the ftp server. Observe that in our approach, every system call is intercepted and subject to potentially expensive operations for matching against many patterns that specify normal/abnormal behavior. Thus, minimizing the overheads incurred for pattern-matching is critical for the viability of our approach. We solve this problem by developing a new, low-overhead algorithm for matching runtime behaviors against specifications. A salient feature of our algorithm is that its runtime is almost independent of the number of patterns. In most cases, it uses a constant amount of time per system call intercepted, and uses a constant amount of storage, both independent of either the size or number of patterns. These benefits make our algorithm useful for many other intrusion detection methods that employ pattern-matching. We describe our algorithm, and evaluate its performance through experiments.