Theory and Techniques for Automatic Generation of Vulnerability-Based Signatures

Theory and Techniques for Automatic Generation of Vulnerability-Based Signatures
复制标题

DOI:
10.1109/tdsc.2008.55
复制
发表时间:
2008-10
影响因子:
7.3
通讯作者:
David Brumley;J. Newsome;D. Song;Hao Wang;S. Jha
David Brumley;J. Newsome;D. Song;Hao Wang;S. Jha
中科院分区:
计算机科学2区
文献类型:
--
作者:
David Brumley;J. Newsome;D. Song;Hao Wang;S. Jha

文献摘要

被引文献

相似文献

在本文中,我们研究了创建\emph{漏洞签名}的问题。漏洞特征码基于程序漏洞,并不特定于任何特定的利用漏洞。易受攻击签名的优点是其质量可以得到保证。具体地说,我们创建的漏洞签名保证了零误报。我们将展示如何为运行时监视器可以检测到的任何漏洞自动创建特征码。我们给出了漏洞签名的形式化定义,并研究了创建和匹配漏洞签名的计算复杂性。我们系统地探索了漏洞签名的设计空间。我们还提供了在各种语言类中创建漏洞签名的特定技术。为了演示我们的技术,我们构建了一个原型系统。我们的实验表明,使用单个漏洞攻击,我们可以将漏洞签名自动生成为正则表达式、小程序或约束系统。我们演示了创建可通过多个程序路径利用的漏洞签名的技术。我们的结果表明,我们的方法是一种可行的签名生成方法,特别是当需要保证签名时。
In this paper, we explore the problem of creating \emph{vulnerability signatures}. A vulnerability signature is based on a program vulnerability, and is not specific to any particular exploit. The advantage of vulnerability signatures is that their quality can be guaranteed. In particular, we create vulnerability signatures which are guaranteed to have zero false positives. We show how to automate signature creation for any vulnerability that can be detected by a runtime monitor. We provide a formal definition of a vulnerability signature, and investigate the computational complexity of creating and matching vulnerability signatures. We systematically explore the design space of vulnerability signatures. We also provide specific techniques for creating vulnerability signatures in a variety of language classes. In order to demonstrate our techniques, we have built a prototype system. Our experiments show that we can, using a single exploit, automatically generate a vulnerability signature as a regular expression, as a small program, or as a system of constraints. We demonstrate techniques for creating signatures of vulnerabilities which can be exploited via multiple program paths. Our results indicate that our approach is a viable option for signature generation, especially when guarantees are desired.