Environment-sensitive intrusion detection

被引:0
|
作者
Giffin, JT
Dagon, D
Jha, S
Lee, W
Miller, BP
机构
[1] Univ Wisconsin, Dept Comp Sci, Madison, WI 53706 USA
[2] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
来源
关键词
model-based anomaly detection; Dyck model; static binary analysis; static data-flow analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We perform host-based intrusion detection by constructing a model from a program's binary code and then restricting the program's execution by the model. We improve the effectiveness of such model-based intrusion detection systems by incorporating into the model knowledge of the environment in which the program runs, and by increasing the accuracy of our models with a new data-flow analysis algorithm for context-sensitive recovery of static data. The environment-configuration files, command-line parameters, and environment variables-constrains acceptable process execution. Environment dependencies added to a program model update the model to the current environment at every program execution. Our new static data-flow analysis associates a program's data flows with specific calling contexts that use the data. We use this analysis to differentiate system-call arguments flowing from distinct call sites in the program. Using a new average reachability measure suitable for evaluation of call-stack-based program models, we demonstrate that our techniques improve the precision of several test programs' models from 76% to 100%.
引用
收藏
页码:185 / 206
页数:22
相关论文
共 50 条
  • [1] Environment-Sensitive cloning in images
    Zhang, Yun
    Tong, Ruofeng
    VISUAL COMPUTER, 2011, 27 (6-8): : 739 - 748
  • [2] Environment-Sensitive cloning in images
    Yun Zhang
    Ruofeng Tong
    The Visual Computer, 2011, 27 : 739 - 748
  • [3] ENVIRONMENT-SENSITIVE MACHINING OF NONMETALS
    WESTWOOD, AR
    AMERICAN CERAMIC SOCIETY BULLETIN, 1972, 51 (04): : 319 - &
  • [4] FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud
    Jia, Xiaoqi
    Zhou, Guangzhe
    Huang, Qingjia
    Zhang, Weijuan
    Tian, Donghai
    DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2017, 2018, 216 : 3 - 17
  • [5] Detecting Environment-Sensitive Malware
    Lindorfer, Martina
    Kolbitsch, Clemens
    Comparetti, Paolo Milani
    RECENT ADVANCES IN INTRUSION DETECTION, 2011, 6961 : 338 - 357
  • [6] ENVIRONMENT-SENSITIVE FRACTURE - DESIGN CONSIDERATIONS
    TOMKINS, B
    SCOTT, PM
    METALS TECHNOLOGY, 1982, 9 (JUN): : 240 - 248
  • [7] Environment-Sensitive Nanofibers and Anchoring of Dyes
    Ge, Liqin
    Wang, Weichen
    Yao, Chong
    Xu, Zeying
    ASIAN JOURNAL OF CHEMISTRY, 2013, 25 (03) : 1270 - 1274
  • [8] Environment-sensitive hydrogels for drug delivery
    Qiu, Yong
    Park, Kinam
    ADVANCED DRUG DELIVERY REVIEWS, 2012, 64 : 49 - 60
  • [9] Biologically Environment-Sensitive Fluorescent Probes
    Wang Ke
    Ma Huimin
    PROGRESS IN CHEMISTRY, 2010, 22 (08) : 1633 - 1640
  • [10] An Environment-Sensitive Synthetic Microbial Ecosystem
    Hu, Bo
    Du, Jin
    Zou, Rui-yang
    Yuan, Ying-jin
    PLOS ONE, 2010, 5 (05):