Skip to main navigation Skip to search Skip to main content

Comprehensive shellcode detection using runtime heuristics

  • Niometrics
  • Foundation for Research and Technology-Hellas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

61 Scopus citations

Abstract

A promising method for the detection of previously unknown code injection attacks is the identification of the shellcode that is part of the attack vector using payload execution. Existing systems based on this approach rely on the self-decrypting behavior of polymorphic code and can identify only that particular class of shellcode. Plain, and more importantly, metamorphic shellcode do not carry a decryption routine nor exhibit any self-modifications and thus both evade existing detection systems. In this paper, we present a comprehensive shellcode detection technique that uses a set of runtime heuristics to identify the presence of shellcode in arbitrary data streams. We have identified fundamental machine-level operations that are inescapably performed by different shellcode types, based on which we have designed heuristics that enable the detection of plain and metamorphic shellcode regardless of the use of self-decryption. We have implemented our technique in Gene, a code injection attack detection system based on passive network monitoring. Our experimental evaluation and real-world deployment show that Gene can effectively detect a large and diverse set of shellcode samples that are currently missed by existing detectors, while so far it has not generated any false positives.

Original languageEnglish
Title of host publicationProceedings - 26th Annual Computer Security Applications Conference, ACSAC 2010
PublisherIEEE Computer Society
Pages287-296
Number of pages10
ISBN (Print)9781450301336
DOIs
StatePublished - 2010

Publication series

NameProceedings - Annual Computer Security Applications Conference, ACSAC
ISSN (Print)1063-9527

Keywords

  • code emulation
  • payload execution
  • shellcode detection

Fingerprint

Dive into the research topics of 'Comprehensive shellcode detection using runtime heuristics'. Together they form a unique fingerprint.

Cite this