Skip to main navigation Skip to search Skip to main content

Real-world polymorphic attack detection using network-level emulation

  • Agency for Science, Technology and Research, Singapore
  • Foundation for Research and Technology-Hellas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

As state-of-the-art attack detection technology becomes more prevalent, attackers have started to employ techniques such as code obfuscation and polymorphism to defeat these defenses. We have recently proposed network-level emulation, a heuristic detection method that scans network traffic to detect polymorphic attacks. Our approach uses a CPU emulator to dynamically analyze every potential instruction sequence in the inspected traffic, aiming to identify the execution behavior of certain malicious code classes, such as self-decrypting polymorphic shellcode. Network-level emulation does not rely on any exploit or vulnerability specific signatures, which allows the detection of previously unknown attacks, while the actual execution of the attack code makes the detector robust to evasion techniques such as self-modifying code. After more than a year of continuous operation in production networks, our prototype implementation has captured more than a million attacks against real systems, employing a highly diverse set of exploits, often against less widely used vulnerable services, while so far has not resulted to any false positives.

Original languageEnglish
Title of host publicationCSIIRW'08 - 4th Annual Cyber Security and Information Intelligence Research Workshop
Subtitle of host publicationDeveloping Strategies to Meet the Cyber Security and Information Intelligence Challenges Ahead
DOIs
StatePublished - 2008
Event4th Annual Cyber Security and Information Intelligence Research Workshop: Developing Strategies to Meet the Cyber Security and Information Intelligence Challenges Ahead, CSIIRW'08 - Oak Ridge, TN, United States
Duration: May 12 2008May 14 2008

Publication series

NameCSIIRW'08 - 4th Annual Cyber Security and Information Intelligence Research Workshop: Developing Strategies to Meet the Cyber Security and Information Intelligence Challenges Ahead

Conference

Conference4th Annual Cyber Security and Information Intelligence Research Workshop: Developing Strategies to Meet the Cyber Security and Information Intelligence Challenges Ahead, CSIIRW'08
Country/TerritoryUnited States
CityOak Ridge, TN
Period05/12/0805/14/08

Keywords

  • Emulation
  • Intrusion detection
  • Polymorphism
  • Shellcode

Fingerprint

Dive into the research topics of 'Real-world polymorphic attack detection using network-level emulation'. Together they form a unique fingerprint.

Cite this