DocumentCode
474877
Title
Scalable network-based buffer overflow attack detection
Author
Hsu, Fu-Hau ; Guo, Fanglu ; Chiueh, Tzi-cker
Author_Institution
Dept. of Comput. Sci. & Inf. Eng., Nat. Central Univ., Taoyuan
fYear
2006
fDate
3-5 Dec. 2006
Firstpage
163
Lastpage
172
Abstract
Buffer overflow attack is the main attack method that most if not all existing malicious worms use to propagate themselves from machine to machine. Although a great deal of research has been invested in defense mechanisms against buffer overflow attack, most of them require modifications to the network applications and/or the platforms that host them. Being an extension work of CTCP, this paper presents a network-based low performance overhead buffer overflow attack detection system called Nebula, which can detect both known and zero-day buffer overflow attacks based solely on the packets observed without requiring any modifications to the end hosts. Moreover, instead of deriving a specific signature for each individual buffer overflow attack instance, Nebula uses a generalized signature that can capture all known variants of buffer overflow attacks while reducing the number of false positives to a negligible level. In addition, Nebula is built on a centralized TCP/IP architecture that effectively defeats all existing NIDS evasion techniques. Finally, Nebula incorporates a payload type identification mechanism that reduces further the false positive rate and scales the proposed buffer overflow attack detection scheme to gigabit network links.
Keywords
invasive software; CTCP; NIDS evasion; Nebula; centralized TCP-IP architecture; gigabit network links; malicious worms; scalable network-based buffer overflow attack detection; zero-day buffer overflow attacks; Buffer overflow; Computer networks; Computer science; Computer worms; Data security; Intrusion detection; Laboratories; Libraries; Payloads; TCPIP; CTCP; buffer overflow attacks; generalized attack signatures; network-based intrusion detection; payload bypassing; return-into-libc attacks;
fLanguage
English
Publisher
ieee
Conference_Titel
Architecture for Networking and Communications systems, 2006. ANCS 2006. ACM/IEEE Symposium on
Conference_Location
San Jose, CA
Print_ISBN
978-1-59593-580-9
Type
conf
Filename
4579534
Link To Document