Accurate and efficient exploit capture and classification
Accurate and efficient exploit capture and classification
复制标题
准确高效的漏洞捕获和分类
DOI:
10.1007/s11432-016-5521-0
复制
发表时间:
2016-09
期刊:
影响因子:
--
通讯作者:
Xinhui HAN
中科院分区:
文献类型:
--
作者:
Yu DING;Tao WEI;Hui XUE;Yulong ZHANG;Chao ZHANG;Xinhui HAN
Software exploits, especially zero-day exploits, are major security threats. Every day, security experts discover and collect numerous exploits from honeypots, malware forensics, and underground channels. However, no easy methods exist to classify these exploits into meaningful categories and to accelerate diagnosis as well as detailed analysis. To address this need, we present SeismoMeter, which recognizes both control-flowhijacking, and data-only attacks by combining approximate control-flow integrity, fast dynamic taint analysis and API sandboxing schemes. Once it detects an exploit incident, SeismoMeter generates a succinct data representation, called an exploit skeleton, to characterize the captured exploit. SeismoMeter then classifies the captured exploits into different exploit families by performing distance computing on the extracted skeletons. To evaluate the efficiency of SeismoMeter, we conduct a field test using exploit samples from public exploit databases, such as Metasploit, as well as wild-captured exploits. Our experiments demonstrate that SeismoMeter is a practical system that successfully detects and correctly classifies all these exploit attacks.
登录
查看更多内容
影响因子:
3.9
作者:
C. Cowan
通讯作者:
C. Cowan
DOI:
10.1145/1272996.1273010
发表时间:
2007-03
期刊:
--
影响因子:
--
作者:
Joseph A. Tucek;J. Newsome;Shan Lu;Chengdu Huang;S. Xanthos;David Brumley;Yuanyuan Zhou;D. Song
通讯作者:
Joseph A. Tucek;J. Newsome;Shan Lu;Chengdu Huang;S. Xanthos;David Brumley;Yuanyuan Zhou;D. Song
影响因子:
--
作者:
Luk, CK;Cohn, R;Hazelwood, K
通讯作者:
Hazelwood, K
DOI:
--
发表时间:
2007
期刊:
--
影响因子:
--
作者:
Min Xu
通讯作者:
Min Xu
DOI:
--
发表时间:
2009-04
期刊:
--
影响因子:
--
作者:
Jose Nazario
通讯作者:
Jose Nazario