全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Detecting Polymorphic Buffer Overflow Exploits with a Static Analysis Approach

DOI: 10.5815/ijwmt.2011.01.03

Keywords: Exploit Code , Polymorphism , Abstract Execution , Symbolic Execution , NOOP Instruction Sequence

Full-Text   Cite this paper   Add to My Lib

Abstract:

Remote exploit attacks are the most serious threats in network security area. Polymorphism is a kind of code-modifying technique used to evade detection. A novel approach using static analysis methods is proposed to discover the polymorphic exploit codes hiding in network data flows. The idea of abstract execution is firstly adopted to construct control flow graph, then both symbolic execution and taint analysis are used to detect exploit payloads, at last predefined length of NOOP instruction sequence is recognized to help detection. Experimental results show that the approach is capable of correctly distinguishing the exploit codes from regular network flows.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133