Detection of Sophisticated Network Enabled Threats via a Novel Micro-Proxy Architecture
- 1 Information Security Research Group, University of South Wales, Pontypridd, UK
Abstract
With the increasing use of novel exploitation techniques in modern malicious software it can be argued that current intrusion detection and intrusion prevention systems are failing to keep pace. While some intrusion prevention systems have the capability to detect evasion techniques they all fail to detect novel unknown exploitation techniques. Traditional proxy approaches have failed to protect the universe of discourse that a network enabled service can be engaged in as they view all information flows of the same type in a uniform manner. In this paper we propose a micro-proxy architecture that utilizes reverse engineering techniques to identify a valid universe of discourse for a network service. This valid universe of discourse is then applied to validate legitimate transactions to a service. Thus in effect, the micro proxy implements a default deny policy via the analysis of the application level discourse.
- Bass, T. (2000) Intrusion Detection Systems and Multi-Sensor Data Fusion. Communications of the ACM, 43, 4. http://dx.doi.org/10.1145/332051.332079
- Cova, M., Felmetsger, V., Banks, G. and Vigna, G. (2006) Static Detection of Vulnerabilities in x86 Executables. ACSAC ‘06 Proceedings of the 22nd Annual Computer Security Applications Conference, Miami Beach, December 2006, 269-278.
- Mutz, D., Valeur, F., Vigna, G. and Kruegel, C. (2006) Anomalous System Call Detection. ACM Transactions on Information and System Security, 9, 1. http://dx.doi.org/10.1145/1127345.1127348
- Wang, T. and Roychoudhury, A. (2007) Hierarchical Dynamic Slicing. Proceedings of the 2007 International Symposium on Software Testing and Analysis, 228-238.
- Zhang, X. and Gupta, R. (2004) Whole Execution Traces. 37th International Symposium on Microarchitectures. IEEE Press.
- Zheng, J., Williams, L., Nagappan, N., Snipes, W., Hudepohl, J. and Vouk, M. (2006) On the Value of Static Analysis for Fault Detection in Software. IEEE Transactions on Software Engineering, 32, 240-253. http://dx.doi.org/10.1109/TSE.2006.38
- Hovemeyer, D. and Pugh, W. (2004) Finding Bugs Is Easy. Proceedings of the 19th ACM Conference on ObjectOriented Programming, Systems, Languages, and Applications, Vancouver.
- Heckman, S. and Williams, L. (2009) A Model Building Process for Identifying Actionable Static Analysis Alerts. Proceedings of the 2nd IEEE International Conference on Software Testing, Verification and Validation, Denver, 1-4 April 2009, 161-170.
- Chess, B. and McGraw, G. (2004) Static Analysis for Security. IEEE Security & Privacy, 2, 76-79. http://dx.doi.org/10.1109/MSP.2004.111
- Yi, K., Choi, H., Kim, J. and Kim, Y. (2007) An Empirical Study on Classification Methods for Alarms from a BugFinding Static C Analyzer. Information Processing Letters, 102, 118-123. http://dx.doi.org/10.1016/j.ipl.2006.11.004
- Schwartz, E.J., Avgerinos, T. and Brumley, D. (2010) All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but Might Have Been Afraid to Ask). Proceedings of the 2010 IEEE Symposium on Security and Privacy, Oakland, 16-19 May 2010, 317-331. http://dx.doi.org/10.1109/SP.2010.26
- Cavallaro, L., Saxena, P. and Sekar, R. (2008) On the Limits of Information Flow Techniques for Malware Analysis and Containment. Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), Springer.