DocumentCode
1867892
Title
Detecting Return-to-libc Buffer Overflow Attacks Using Network Intrusion Detection Systems
Author
Day, David J. ; Zhao, Zhengxu ; Ma, Minhua
Author_Institution
Sch. of Comput., Univ. of Derby, Derby, UK
fYear
2010
fDate
10-16 Feb. 2010
Firstpage
172
Lastpage
177
Abstract
There has been a significant amount of research recently into methods of protecting systems from buffer overflow attacks by detecting stack injected shell code. The majority of the research focuses on developing algorithms or signatures for detecting polymorphic and metamorphic payloads. However much of this problem has already been solved through the mainstream use of host based protection mechanisms e.g. Data Execution Prevention (DEP) and Address Space Randomization (ASLR). Many hackers are now using the more inventive attack methods e.g., return-to-libc, which do not inject shell code onto the stack and thus evade DEP and common shell code detection mechanisms. The purpose of this work is to propose a series of generic signatures that could be used to detect network born return-to-libc attacks. To this end we outline how we performed a return-to-libc network based attack, which bypasses DEP and common IDS signatures, before suggesting an efficient signature for detection of similar return-to-libc attacks.
Keywords
buffer storage; digital signatures; buffer overflow attack; generic signature; metamorphic payload; network intrusion detection system; polymorphic payload; return-to-libc network based attack; Buffer overflow; Computer bugs; Computer hacking; Computer networks; Computer worms; Functional programming; Internet; Intrusion detection; Payloads; Protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Digital Society, 2010. ICDS '10. Fourth International Conference on
Conference_Location
St. Maarten
Print_ISBN
978-1-4244-5805-9
Type
conf
DOI
10.1109/ICDS.2010.37
Filename
5432802
Link To Document