ISCAS OpenIR
autodunt: dynamic latent dependence analysis for detection of zero day vulnerability
Chen Kai; Lian Yifeng; Zhang Yingjun
2012
会议名称14th International Conference on Information Security and Cryptology, ICISC 2011
会议录名称Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
页码140-154
会议日期November 30, 2011 - December 2, 2011
会议地点Seoul, Korea, Republic of
收录类别EI
ISSN0302-9743
ISBN9783642319112
部门归属(1) Institute of Software Chinese Academy of Sciences Beijing 100190 China; (2) National Engineering Research Center for Information Security Beijing 100190 China
摘要Zero day vulnerabilities have played an important role in cyber security. Since they are unknown to the public and patches are not available, hackers can use them to attack effectively. Detecting software vulnerabilities and making patches could protect hosts from attacks that use these vulnerabilities. But this method cannot prevent all vulnerabilities. Some methods such as address space randomization could defend against vulnerabilities, but they cannot find them in software to help software vendors to generate patches for other hosts. In this paper, we design and develop a proof-of-concept prototype called AutoDunt (AUTOmatical zero Day vUlNerability deTector), which can detect vulnerable codes in software by analyzing attacks directly in virtual surroundings. It does not need any source codes or care about polymorphic/metamorphic shellcode (even no shellcode). We present a new kind of dependence between variables called latent dependence and use it to save necessary states for virtual surrounding replaying. In this way, AutoDunt does not need to use slicing or taint analysis method to find the vulnerable code in software, which saves managing time. We verify the effectiveness and evaluate the efficiency of AutoDunt by testing 81 real exploits and 7 popular applications at the end of this paper. © 2012 Springer-Verlag.; Zero day vulnerabilities have played an important role in cyber security. Since they are unknown to the public and patches are not available, hackers can use them to attack effectively. Detecting software vulnerabilities and making patches could protect hosts from attacks that use these vulnerabilities. But this method cannot prevent all vulnerabilities. Some methods such as address space randomization could defend against vulnerabilities, but they cannot find them in software to help software vendors to generate patches for other hosts. In this paper, we design and develop a proof-of-concept prototype called AutoDunt (AUTOmatical zero Day vUlNerability deTector), which can detect vulnerable codes in software by analyzing attacks directly in virtual surroundings. It does not need any source codes or care about polymorphic/metamorphic shellcode (even no shellcode). We present a new kind of dependence between variables called latent dependence and use it to save necessary states for virtual surrounding replaying. In this way, AutoDunt does not need to use slicing or taint analysis method to find the vulnerable code in software, which saves managing time. We verify the effectiveness and evaluate the efficiency of AutoDunt by testing 81 real exploits and 7 popular applications at the end of this paper. © 2012 Springer-Verlag.
关键词Cryptography Personal Computing
主办者National Security Research Institute (NSRI); Electronics and Telecommunications Research Institute (ETRI); Korea Internet and Security Agency (KISA); Ministry of Public Administration and Security (MOPAS)
语种英语
内容类型会议论文
URI标识http://ir.iscas.ac.cn/handle/311060/15777
专题中国科学院软件研究所
推荐引用方式
GB/T 7714
Chen Kai,Lian Yifeng,Zhang Yingjun. autodunt: dynamic latent dependence analysis for detection of zero day vulnerability[C],2012:140-154.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Chen Kai]的文章
[Lian Yifeng]的文章
[Zhang Yingjun]的文章
百度学术
百度学术中相似的文章
[Chen Kai]的文章
[Lian Yifeng]的文章
[Zhang Yingjun]的文章
必应学术
必应学术中相似的文章
[Chen Kai]的文章
[Lian Yifeng]的文章
[Zhang Yingjun]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。