DocumentCode :
474877
Title :
Scalable network-based buffer overflow attack detection
Author :
Hsu, Fu-Hau ; Guo, Fanglu ; Chiueh, Tzi-cker
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Central Univ., Taoyuan
fYear :
2006
fDate :
3-5 Dec. 2006
Firstpage :
163
Lastpage :
172
Abstract :
Buffer overflow attack is the main attack method that most if not all existing malicious worms use to propagate themselves from machine to machine. Although a great deal of research has been invested in defense mechanisms against buffer overflow attack, most of them require modifications to the network applications and/or the platforms that host them. Being an extension work of CTCP, this paper presents a network-based low performance overhead buffer overflow attack detection system called Nebula, which can detect both known and zero-day buffer overflow attacks based solely on the packets observed without requiring any modifications to the end hosts. Moreover, instead of deriving a specific signature for each individual buffer overflow attack instance, Nebula uses a generalized signature that can capture all known variants of buffer overflow attacks while reducing the number of false positives to a negligible level. In addition, Nebula is built on a centralized TCP/IP architecture that effectively defeats all existing NIDS evasion techniques. Finally, Nebula incorporates a payload type identification mechanism that reduces further the false positive rate and scales the proposed buffer overflow attack detection scheme to gigabit network links.
Keywords :
invasive software; CTCP; NIDS evasion; Nebula; centralized TCP-IP architecture; gigabit network links; malicious worms; scalable network-based buffer overflow attack detection; zero-day buffer overflow attacks; Buffer overflow; Computer networks; Computer science; Computer worms; Data security; Intrusion detection; Laboratories; Libraries; Payloads; TCPIP; CTCP; buffer overflow attacks; generalized attack signatures; network-based intrusion detection; payload bypassing; return-into-libc attacks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Architecture for Networking and Communications systems, 2006. ANCS 2006. ACM/IEEE Symposium on
Conference_Location :
San Jose, CA
Print_ISBN :
978-1-59593-580-9
Type :
conf
Filename :
4579534
Link To Document :
بازگشت