Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving Approach

Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving Approach
复制标题

DOI:
10.1109/tpds.2007.70765
复制
发表时间:
2008-07
影响因子:
5.3
通讯作者:
Xuxian Jiang;Florian P. Buchholz;Aaron Walters;Dongyan Xu;Yi-Min Wang;E. Spafford
Xuxian Jiang;Florian P. Buchholz;Aaron Walters;Dongyan Xu;Yi-Min Wang;E. Spafford
中科院分区:
计算机科学2区
文献类型:
--
作者:
Xuxian Jiang;Florian P. Buchholz;Aaron Walters;Dongyan Xu;Yi-Min Wang;E. Spafford

文献摘要

被引文献

相似文献

为了检测和调查针对联网服务器的自传播蠕虫攻击,需要以下能力:1)及时发出警报以触发蠕虫调查,2)确定蠕虫的侵入点,即,蠕虫从中渗透受害者的易受攻击的服务,以及3)识别蠕虫在其驻留在受害者中期间所造成的所有污染。在本文中,我们认为,在实现这些功能,并没有被利用的蠕虫入侵起源信息,从而提出进程着色,一种新的方法,保留蠕虫入侵起源信息,并传播它沿着操作系统级的信息流。更具体地说,进程着色为每个可远程访问的服务器进程分配一个“颜色”,一个唯一的系统范围标识符。颜色将被派生的子进程继承,或者通过进程操作传递扩散。进程着色实现了三个新功能:基于颜色的蠕虫警告生成、入侵点识别和日志文件分区。基于虚拟化的实施支持更防篡改的日志收集、存储和实时监控。除了虚拟化引入的开销之外,进程着色只会带来非常小的额外系统开销。与真实世界的蠕虫实验证明了处理着色的优势,非原产地保护工具。
To detect and investigate self-propagating worm attacks against networked servers, the following capabilities are desirable: 1) raising timely alerts to trigger a worm investigation, 2) determining the break-in point of a worm, i.e., the vulnerable service from which the worm infiltrates the victim, and 3) identifying all contaminations inflicted by the worm during its residence in the victim. In this paper, we argue that the worm break-in provenance information has not been exploited in achieving these capabilities and thus propose process coloring, a new approach that preserves worm break-in provenance information and propagates it along operating- system-level information flows. More specifically, process coloring assigns a "color," a unique systemwide identifier, to each remotely accessible server process. The color will be either inherited by spawned child processes or diffused transitively through process actions. Process coloring achieves three new capabilities: color-based worm warning generation, break-in point identification, and log file partitioning. The virtualization-based implementation enables more tamper-resistant log collection, storage, and real-time monitoring. Beyond the overhead introduced by virtualization, process coloring only incurs very small additional system overhead. Experiments with real-world worms demonstrate the advantages of processing coloring over non-provenance-preserving tools.