TY - GEN
T1 - Stride
T2 - IFIP TC11 20th International Information Security Conference, IFIP/SEC2005
AU - Akritidis, P.
AU - Markatos, E. P.
AU - Polychronakis, M.
AU - Anagnostakis, K.
PY - 2005
Y1 - 2005
N2 - Despite considerable effort, buffer overflow attacks remain a major security threat today, especially when coupled with self-propagation mechanisms as in worms and viruses. This paper considers the problem of designing network-level mechanisms for detecting polymorphic instances of such attacks. The starting point for our work is the observation that many buffer overflow attacks require a "sled" component to transfer control of the system to the exploit code. While previous work has shown that it is possible to detect certain types of sleds, including obfuscated instances, this paper demonstrates that the proposed detection heuristics can be thwarted by more elaborate sled obfuscation techniques. To address this problem, we have designed a new sled detection heuristic, called STRIDE, that offers three main improvements over previous work: it detects several types of sleds that other techniques are blind to, has a lower rate of false positives, and is significantly more computationally efficient, and hence more suitable for use at the network-level.
AB - Despite considerable effort, buffer overflow attacks remain a major security threat today, especially when coupled with self-propagation mechanisms as in worms and viruses. This paper considers the problem of designing network-level mechanisms for detecting polymorphic instances of such attacks. The starting point for our work is the observation that many buffer overflow attacks require a "sled" component to transfer control of the system to the exploit code. While previous work has shown that it is possible to detect certain types of sleds, including obfuscated instances, this paper demonstrates that the proposed detection heuristics can be thwarted by more elaborate sled obfuscation techniques. To address this problem, we have designed a new sled detection heuristic, called STRIDE, that offers three main improvements over previous work: it detects several types of sleds that other techniques are blind to, has a lower rate of false positives, and is significantly more computationally efficient, and hence more suitable for use at the network-level.
KW - buffer overflow detection
KW - intrusion detection
KW - security
UR - https://www.scopus.com/pages/publications/84866362135
U2 - 10.1007/0-387-25660-1_25
DO - 10.1007/0-387-25660-1_25
M3 - Conference contribution
AN - SCOPUS:84866362135
SN - 038725658X
SN - 9780387256580
SN - 9780387256580
T3 - IFIP Advances in Information and Communication Technology
SP - 375
EP - 391
BT - Security and Privacy in the Age of Ubiquitous Computing - IFIP TC11 20th International Information Security Conference
Y2 - 30 May 2005 through 1 June 2005
ER -