Sweeper: a lightweight end-to-end system for defending against fast worms

Sweeper: a lightweight end-to-end system for defending against fast worms
复制标题

DOI:
10.1145/1272996.1273010
复制
发表时间:
2007-03
期刊:
--
影响因子:
--
通讯作者:
Joseph A. Tucek;J. Newsome;Shan Lu;Chengdu Huang;S. Xanthos;David Brumley;Yuanyuan Zhou;D. Song
Joseph A. Tucek;J. Newsome;Shan Lu;Chengdu Huang;S. Xanthos;David Brumley;Yuanyuan Zhou;D. Song
中科院分区:
其他
文献类型:
--
作者:
Joseph A. Tucek;J. Newsome;Shan Lu;Chengdu Huang;S. Xanthos;David Brumley;Yuanyuan Zhou;D. Song

文献摘要

被引文献

相似文献

困扰计算机的漏洞给用户带来了无尽的痛苦。Slammer在几分钟内入侵了数百万台主机;攻击名单蠕虫只需要一秒钟。最近提出的技术响应比人工方法更好,但需要昂贵的仪器,这限制了部署。尽管传播“抗体”(如特征)改善了这一限制,但依赖抗体的宿主在接种前是毫无防御能力的;对于速度最快的蠕虫来说,这种延迟是至关重要的。此外,最近提出的大多数技术都不能提供在攻击后提供持续服务的恢复。我们提出了一种新的解决方案,称为Sweeper,它提供了快速准确的攻击后分析和高效的恢复,正常执行开销低。Sweeper创新地结合了几种技术:(1)Sweeper使用轻量级监控技术来检测各种可疑请求,提供第一级防御。(2)通过巧妙地利用轻量级检查点,Sweeper将重量级监视推迟到绝对必要的时候——在检测到攻击之后。Sweeper回滚并重新执行多次,通过动态二进制检测动态应用重量级分析技术。由于只分析了攻击中涉及的执行,因此分析既有效又彻底。(3)根据分析结果,Sweeper自动生成低开销抗体,防止未来对同一漏洞的攻击。(4)最后,再次重新执行Sweeper,快速恢复,继续服务。我们在一个真实的系统中实现了Sweeper。我们在三个真实服务器和四个真实安全漏洞上的实验结果表明,Sweeper可以在60毫秒内检测到攻击并产生抗体。我们的结果还表明,在正常执行期间,Sweeper的开销不到1%,显然适合广泛的生产部署(特别是因为Sweeper也允许部分部署)。最后,我们分析表明,对于一个能够在一秒钟内感染所有脆弱主机的快速攻击列表蠕虫,Sweeper包含的感染程度低于5%。
The vulnerabilities that plague computers cause endless grief to users. Slammer compromised millions of hosts in minutes; a hit-list worm would take under a second. Recently proposed techniques respond better than manual approaches, but require expensive instrumentation, which limits deployment. Although spreading "antibodies" (e.g. signatures) ameliorates this limitation, hosts depending on antibodies are defenseless until inoculation; to the fastest hit-list worms this delay is crucial. Additionally, most recently proposed techniques cannot provide recovery to provide continuous service after an attack. We propose a novel solution called Sweeper that provides both fast and accurate post-attack analysis and efficient recovery with low normal execution overhead. Sweeper in-novatively combines several techniques: (1) Sweeper uses lightweight monitoring techniques to detect a wide array of suspicious requests, providing a first level of defense. (2) By cleverly leveraging lightweight checkpointing, Sweeper postpones heavyweight monitoring until absolutely necessary --- after an attack is detected. Sweeper rolls back and re-executes multiple times to dynamically apply heavyweight analysis techniques via dynamic binary instrumentation. Since only the execution involved in the attack is analyzed, the analysis is efficient, yet thorough. (3) Based on the analysis results, Sweeper automatically generates low-overhead antibodies to prevent future attacks of the same vulnerability. (4) Finally, Sweeper again re-executes to perform fast recovery for continuous service. We implement Sweeper in a real system. Our experimental results with three real-world servers and four real security vulnerabilities show that Sweeper can detect an attack and generate antibodies in under 60 milliseconds. Our results also show that Sweeper imposes under 1% overhead during normal execution, clearly suitable for widespread production deployment (especially since Sweeper also allows partial deployment). Finally, we analytically show that, for a fast hit-list worm otherwise capable of infecting all vulnerable hosts in under a second, Sweeper contains the extent of infection to under 5%.