Skip to main navigation Skip to search Skip to main content

Network-level polymorphic shellcode detection using emulation

  • Agency for Science, Technology and Research, Singapore
  • Foundation for Research and Technology-Hellas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

40 Scopus citations

Abstract

As state-of-the-art attack detection technology becomes more prevalent, attackers are likely to evolve, employing techniques such as polymorphism and metamorphism to evade detection. Although recent results have been promising, most existing proposals can be defeated using only minor enhancements to the attack vector. We present a heuristic detection method that scans network traffic streams for the presence of polymorphic shellcode. Our approach relies on a NIDS-embedded CPU emulator that executes every potential instruction sequence, aiming to identify the execution behavior of polymorphic shellcodes. Our analysis demonstrates that the proposed approach is more robust to obfuscation techniques like self-modifications compared to previous proposals, but also highlights advanced evasion techniques that need to be more closely examined towards a satisfactory solution to the polymorphic shellcode detection problem.

Original languageEnglish
Title of host publicationDetection of Intrusions and Malware and Vulnerability Assessment - Third International Conference, DIMVA 2006, Proceedings
PublisherSpringer Verlag
Pages54-73
Number of pages20
ISBN (Print)354036014X, 9783540360148
DOIs
StatePublished - 2006
Event3rd International Conference on Detection of Intrusions and Malware and Vulnerability Assessment, DIMVA 2006 - Berlin, Germany
Duration: Jul 13 2006Jul 14 2006

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4064 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference3rd International Conference on Detection of Intrusions and Malware and Vulnerability Assessment, DIMVA 2006
Country/TerritoryGermany
CityBerlin
Period07/13/0607/14/06

Fingerprint

Dive into the research topics of 'Network-level polymorphic shellcode detection using emulation'. Together they form a unique fingerprint.

Cite this