TY - GEN
T1 - Network-level polymorphic shellcode detection using emulation
AU - Polychronakis, Michalis
AU - Anagnostakis, Kostas G.
AU - Markatos, Evangelos P.
PY - 2006
Y1 - 2006
N2 - As state-of-the-art attack detection technology becomes more prevalent, attackers are likely to evolve, employing techniques such as polymorphism and metamorphism to evade detection. Although recent results have been promising, most existing proposals can be defeated using only minor enhancements to the attack vector. We present a heuristic detection method that scans network traffic streams for the presence of polymorphic shellcode. Our approach relies on a NIDS-embedded CPU emulator that executes every potential instruction sequence, aiming to identify the execution behavior of polymorphic shellcodes. Our analysis demonstrates that the proposed approach is more robust to obfuscation techniques like self-modifications compared to previous proposals, but also highlights advanced evasion techniques that need to be more closely examined towards a satisfactory solution to the polymorphic shellcode detection problem.
AB - As state-of-the-art attack detection technology becomes more prevalent, attackers are likely to evolve, employing techniques such as polymorphism and metamorphism to evade detection. Although recent results have been promising, most existing proposals can be defeated using only minor enhancements to the attack vector. We present a heuristic detection method that scans network traffic streams for the presence of polymorphic shellcode. Our approach relies on a NIDS-embedded CPU emulator that executes every potential instruction sequence, aiming to identify the execution behavior of polymorphic shellcodes. Our analysis demonstrates that the proposed approach is more robust to obfuscation techniques like self-modifications compared to previous proposals, but also highlights advanced evasion techniques that need to be more closely examined towards a satisfactory solution to the polymorphic shellcode detection problem.
UR - https://www.scopus.com/pages/publications/33746446345
U2 - 10.1007/11790754_4
DO - 10.1007/11790754_4
M3 - Conference contribution
AN - SCOPUS:33746446345
SN - 354036014X
SN - 9783540360148
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 54
EP - 73
BT - Detection of Intrusions and Malware and Vulnerability Assessment - Third International Conference, DIMVA 2006, Proceedings
PB - Springer Verlag
T2 - 3rd International Conference on Detection of Intrusions and Malware and Vulnerability Assessment, DIMVA 2006
Y2 - 13 July 2006 through 14 July 2006
ER -