Analysis of Computer Intrusions Using Sequences of Function Calls

Analysis of Computer Intrusions Using Sequences of Function Calls
复制标题

使用函数调用序列分析计算机入侵

DOI:
10.1109/tdsc.2007.1003
复制
发表时间:
2007
影响因子:
7.3
通讯作者:
K. Marzullo
K. Marzullo
中科院分区:
计算机科学2区
文献类型:
--
作者:
S. Peisert;M. Bishop;Sidney Karin;K. Marzullo

文献摘要

被引文献

相似文献

本文论证了分析函数调用序列对于取证分析的价值。尽管这种方法已用于入侵检测(即确定系统已受到攻击),但其在隔离攻击原因和影响方面的价值以前尚未显示出来。我们不仅寻找意外事件的存在,而且寻找预期事件的不存在。我们使用 su、ssh 和 lpr 中的重构漏洞以及概念验证代码来测试这些技术,并且在所有情况下都能够检测到异常情况和漏洞的性质。
This paper demonstrates the value of analyzing sequences of function calls for forensic analysis. Although this approach has been used for intrusion detection (that is, determining that a system has been attacked), its value in isolating the cause and effects of the attack has not previously been shown. We also look for not only the presence of unexpected events but also the absence of expected events. We tested these techniques using reconstructed exploits in su, ssh, and lpr, as well as proof-of-concept code, and, in all cases, were able to detect the anomaly and the nature of the vulnerability.