Skip to main navigation Skip to search Skip to main content

Emulation-based detection of non-self-contained polymorphic shellcode

  • Agency for Science, Technology and Research, Singapore
  • Foundation for Research and Technology-Hellas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

40 Scopus citations

Abstract

Network-level emulation has recently been proposed as a method for the accurate detection of previously unknown polymorphic code injection attacks. In this paper, we extend network-level emulation along two lines. First, we present an improved execution behavior heuristic that enables the detection of a certain class of non-self-contained polymorphic shellcodes that are currently missed by existing emulation-based approaches. Second, we present two generic algorithmic optimizations that improve the runtime performance of the detector. We have implemented a prototype of the proposed technique and evaluated it using off-the-shelf non-self-contained polymorphic shellcode engines and benign data. The detector achieves a modest processing throughput, which however is enough for decent runtime performance on actual deployments, while it has not produced any false positives. Finally, we report attack activity statistics from a seven-month deployment of our prototype in a production network, which demonstrate the effectiveness and practicality of our approach.

Original languageEnglish
Title of host publicationRecent Advances in Intrusion Detection - 10th International Symposium, RAID 2007, Proceedings
PublisherSpringer Verlag
Pages87-106
Number of pages20
ISBN (Print)9783540743194
DOIs
StatePublished - 2007
Event10th International Symposium on Recent Advances in Intrusion Detection, RAID 2007 - Gold Coast, Australia
Duration: Sep 5 2007Sep 7 2007

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4637 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference10th International Symposium on Recent Advances in Intrusion Detection, RAID 2007
Country/TerritoryAustralia
CityGold Coast
Period09/5/0709/7/07

Fingerprint

Dive into the research topics of 'Emulation-based detection of non-self-contained polymorphic shellcode'. Together they form a unique fingerprint.

Cite this