Semantic aware attribution analysis of remote exploits

Semantic aware attribution analysis of remote exploits
复制标题

DOI:
10.1002/sec.613
复制
发表时间:
2013-07-01
影响因子:
--
通讯作者:
Wu, Dinghao
Wu, Dinghao
中科院分区:
计算机科学4区
文献类型:
--
作者:
Kong, Deguang;Tian, Donghai;Wu, Dinghao

文献摘要

被引文献

相似文献

Web 服务受到远程漏洞利用代码攻击的极大威胁,其中恶意制作的 HTTP 请求被用来注入二进制代码以危害 Web 服务器和 Web 应用程序。在实践中,除了检测此类攻击外,攻击归因分析(即自动对漏洞进行分类或确定漏洞是否是过去攻击的变体)也非常重要。在本文中,我们提出了 SA3,一种新颖的漏洞利用代码归因分析,它结合了基于语义的分析和统计建模来自动对给定的漏洞利用代码进行分类。 SA3 通过数据异常分析从漏洞利用代码中提取语义特征,然后根据从马尔可夫模型导出的统计模型将漏洞归因于适当的类别。我们通过从 Metasploit 和其他多态引擎收集的一组全面的 shellcode 来评估 SA3。实验结果表明SA3是有效且高效的。不同参数设置下归因分析准确率可达90%以上,误报率不超过4.5%。 SA3 的新颖之处在于它将语义分析与统计建模相结合以进行漏洞代码归因分析。版权所有 (c) 2012 John Wiley & Sons, Ltd.
Web services have been greatly threatened by remote exploit code attacks, where maliciously crafted HTTP requests are used to inject binary code to compromise web servers and web applications. In practice, besides detection of such attacks, attack attribution analysis (i.e., to automatically categorize exploits or determine whether an exploit is a variant of an attack from the past) is also very important. In this paper, we present SA3, a novel exploit code attribution analysis that combines semantics-based analysis and statistical modeling to automatically categorize given exploit code. SA3 extracts semantic features from exploit code through data anomaly analysis and then attributes the exploit to an appropriate class on the basis of our statistical model derived from a Markov model. We evaluate SA3 over a comprehensive set of shellcode collected from Metasploit and other polymorphic engines. Experimental results show that SA3 is effective and efficient. The attribution analysis accuracy can be over 90% in different parameter settings with false positive rate no more than 4.5%. The novelty of SA3 is that it combines semantic analysis with statistical modeling for exploit code attribution analysis. Copyright (c) 2012 John Wiley & Sons, Ltd.