TY - GEN
T1 - Emulation-based detection of non-self-contained polymorphic shellcode
AU - Polychronakis, Michalis
AU - Anagnostakis, Kostas G.
AU - Markatos, Evangelos P.
PY - 2007
Y1 - 2007
N2 - Network-level emulation has recently been proposed as a method for the accurate detection of previously unknown polymorphic code injection attacks. In this paper, we extend network-level emulation along two lines. First, we present an improved execution behavior heuristic that enables the detection of a certain class of non-self-contained polymorphic shellcodes that are currently missed by existing emulation-based approaches. Second, we present two generic algorithmic optimizations that improve the runtime performance of the detector. We have implemented a prototype of the proposed technique and evaluated it using off-the-shelf non-self-contained polymorphic shellcode engines and benign data. The detector achieves a modest processing throughput, which however is enough for decent runtime performance on actual deployments, while it has not produced any false positives. Finally, we report attack activity statistics from a seven-month deployment of our prototype in a production network, which demonstrate the effectiveness and practicality of our approach.
AB - Network-level emulation has recently been proposed as a method for the accurate detection of previously unknown polymorphic code injection attacks. In this paper, we extend network-level emulation along two lines. First, we present an improved execution behavior heuristic that enables the detection of a certain class of non-self-contained polymorphic shellcodes that are currently missed by existing emulation-based approaches. Second, we present two generic algorithmic optimizations that improve the runtime performance of the detector. We have implemented a prototype of the proposed technique and evaluated it using off-the-shelf non-self-contained polymorphic shellcode engines and benign data. The detector achieves a modest processing throughput, which however is enough for decent runtime performance on actual deployments, while it has not produced any false positives. Finally, we report attack activity statistics from a seven-month deployment of our prototype in a production network, which demonstrate the effectiveness and practicality of our approach.
UR - https://www.scopus.com/pages/publications/38149093160
U2 - 10.1007/978-3-540-74320-0_5
DO - 10.1007/978-3-540-74320-0_5
M3 - Conference contribution
AN - SCOPUS:38149093160
SN - 9783540743194
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 87
EP - 106
BT - Recent Advances in Intrusion Detection - 10th International Symposium, RAID 2007, Proceedings
PB - Springer Verlag
T2 - 10th International Symposium on Recent Advances in Intrusion Detection, RAID 2007
Y2 - 5 September 2007 through 7 September 2007
ER -