全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Automatic Generation of Attach-based Signature
基于攻击特征签名的自动生成

Keywords: Computer security,Software security,Software vulnerability,Binary signature,Binary patch
计算机安全
,软件安全,软件漏洞,二进制程序签名,二进制补丁

Full-Text   Cite this paper   Add to My Lib

Abstract:

Signatures can be generated based on characteristics of attacks. Using dynamic program analyzing skills we generated binary signatures for control flow attack to return value of function call and function call pointer, and noncontrol flow attack to decision-related variable. First, we identified instructions related to the vulnerability. Second, we monitored these instructions using a modified virtual machine. At last, we alerted and generated signature after finding any malicious write behaviors. Patch recorded malicious write instructions could be generated meanwhile to ignore these instructions in future execution. Generated signature could be sent to other computers to monitor the same software's execution using lightweight virtual machine. Experiment results show that binary level signature has simplified form and precise functionality and low false negative and is effective to defense polymorphic attack. Besides, lightweight virtual machine makes use of the signature fast.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133