• DocumentCode
    1685462
  • Title

    An intrusion detection system using alteration of data

  • Author

    Nagano, Fumiaki ; Tatara, Kohei ; Tabata, Toshihiro ; Sakurai, Kouichi

  • Author_Institution
    Kyushu Univ., Fukuoka, Japan
  • Volume
    1
  • fYear
    2006
  • Abstract
    Attacks against data in memory are one of the most serious threats these days. Although many detection systems have been proposed so far, most of them can detect only part of alteration. Some detection systems use canaries to detect alteration. However, if an execution code has bugs that enable attackers to read data in memory, the system could be bypassed by attackers who can guess canaries. To overcome the problems, we propose a system using alteration of data. Our proposed system detects illegal alteration with verifier for vulnerable data. Verifier is made before vulnerable data could be altered by attackers, and verifier is checked when the program uses the vulnerable data. Part of verifier is stored in kernel area to prevent attackers from reading data in user memory. Our approach can detect illegal alteration of arbitrary data in user memory. Our proposed system, moreover, does not have the problem systems using canaries have.
  • Keywords
    security of data; telecommunication security; attacke; canarie; data alteration; intrusion detection system; kernel area; user memory; verifier; vulnerable data; Buffer overflow; Computer bugs; Cryptography; Data security; Internet; Intrusion detection; Kernel; Libraries; Payloads; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications, 2006. AINA 2006. 20th International Conference on
  • ISSN
    1550-445X
  • Print_ISBN
    0-7695-2466-4
  • Type

    conf

  • DOI
    10.1109/AINA.2006.94
  • Filename
    1620199