• DocumentCode
    3100517
  • Title

    Online Signature Generation for Windows Systems

  • Author

    Li, Lixin ; Just, James E. ; Sekar, R.

  • Author_Institution
    Global InfoTek, Inc., Reston, VA, USA
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    289
  • Lastpage
    298
  • Abstract
    In this paper, we present a new, light-weight approach for generating filters for blocking buffer overflow attacks on Microsoft Windows systems. It is designed to be deployable as an "always on\´\´ component on production systems. To achieve this goal, it avoids expensive and intrusive techniques such as taint-tracking. The online nature of our system enables it to provide protection from a range of memory corruption exploits, including those involving unknown vulnerabilities, or known vulnerabilities but unknown exploits. In contrast, most previous signature generation techniques need to be run in sandboxed environments, and need working exploits to generate signatures. Moreover, our technique overcomes the "gap\´\´ problem faced by previous signature generation mechanisms, i.e., when the vulnerable memory region is corrupted between the overflow and the time an attack is detected. Another novel feature of our approach is that it is able to reason about likely lengths of vulnerable buffers, which can lead to more accurate signatures. Our experimental results are very promising, and demonstrate that the approach can generate effective signatures for many synthetic and real-world vulnerabilities.
  • Keywords
    operating systems (computers); security of data; Microsoft Windows system; buffer overflow attacks blocking method; memory corruption exploits; online signature generation; sandboxed environment; unknown vulnerability; vulnerable memory region; Application software; Automatic speech recognition; Buffer overflow; Computer security; Computer vision; Face detection; Filters; Payloads; Production systems; Protection; buffer overflow; self-healing; signature generation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.34
  • Filename
    5380683