Long-Span Program Behavior Modeling and Attack Detection

被引:20
|
作者
Shu, Xiaokui [1 ]
Yao, Danfeng [2 ]
Ramakrishnan, Naren [3 ]
Jaeger, Trent [4 ]
机构
[1] IBM Res, 1101 Kitchawan Rd, Yorktown Hts, NY 10598 USA
[2] Virginia Tech, 2202 Kraft Dr, Blacksburg, VA 24060 USA
[3] Virginia Tech, VTRC Arlington, Room 5-026,900 North Glebe Rd, Arlington, VA 22203 USA
[4] Penn State Univ, 346A IST Bldg, University Pk, PA 16802 USA
关键词
Intrusion detection; program analysis; anomaly detection; context-sensitive grammar; co-occurrence analysis; event frequency correlation; machine learning; INTRUSION-DETECTION; SYSTEM;
D O I
10.1145/3105761
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intertwined developments between program attacks and defenses witness the evolution of program anomaly detection methods. Emerging categories of program attacks, e.g., non-control data attacks and data-oriented programming, are able to comply with normal trace patterns at local views. This article points out the deficiency of existing program anomaly detection models against new attacks and presents long-span behavior anomaly detection (LAD), a model based on mildly context-sensitive grammar verification. The key feature of LAD is its reasoning of correlations among arbitrary events that occurred in long program traces. It extends existing correlation analysis between events at a stack snapshot, e.g., paired call and ret, to correlation analysis among events that historically occurred during the execution. The proposed method leverages specialized machine learning techniques to probe normal program behavior boundaries in vast high-dimensional detection space. Its two-stage modeling/detection design analyzes event correlation at both binary and quantitative levels. Our prototype successfully detects all reproduced real-world attacks against sshd, libpcre, and sendmail. The detection procedure incurs 0.1 ms to 1.3 ms overhead to profile and analyze a single behavior instance that consists of tens of thousands of function call or system call events.
引用
收藏
页数:28
相关论文
共 50 条
  • [21] INVESTIGATION ON FLEXURAL BEHAVIOR OF FERROCEMENT AND ITS APPLICATION TO LONG-SPAN ROOFS
    KARIM, EA
    JOSEPH, GP
    JOURNAL OF FERROCEMENT-BANGKOK, 1978, 8 (01): : 1 - 21
  • [22] AEROELASTIC BEHAVIOR OF LONG-SPAN BRIDGES WITH MULTIBOX TYPE DECK SECTIONS
    PECORA, M
    LECCE, L
    MARULO, F
    COIRO, DP
    JOURNAL OF WIND ENGINEERING AND INDUSTRIAL AERODYNAMICS, 1993, 48 (2-3) : 343 - 358
  • [23] Punching and fatigue behavior of long-span prestressed concrete deck slabs
    Hwang, Hoonhee
    Yoon, Hyejin
    Joh, Changbin
    Kim, Byung-Suk
    ENGINEERING STRUCTURES, 2010, 32 (09) : 2861 - 2872
  • [24] Study on the mechanical behavior of long-span steel truss transfer storey
    He Mingwei
    CIVIL, STRUCTURAL AND ENVIRONMENTAL ENGINEERING, PTS 1-4, 2014, 838-841 : 219 - 226
  • [25] Crack Detection and Analysis of Long-span Continuous Rigid Frame Bridges
    Liu Kang
    Wu Bo
    Yuan Yuan
    APPLIED MATERIALS AND TECHNOLOGIES FOR MODERN MANUFACTURING, PTS 1-4, 2013, 423-426 : 1193 - 1197
  • [26] Operational deformations in long-span bridges
    Brownjohn, James M. W.
    Koo, Ki-Young
    Scullion, Andrew
    List, David
    STRUCTURE AND INFRASTRUCTURE ENGINEERING, 2015, 11 (04) : 556 - 574
  • [27] Research on long-span suspension clamp
    Liu Zhen
    Liu Shengchun
    Sun Na
    FRONTIERS OF CHEMICAL ENGINEERING, METALLURGICAL ENGINEERING AND MATERIALS II, 2013, 803 : 454 - 458
  • [28] On buffeting responses of long-span bridges
    Li, Mingshui
    Wang, Weihua
    Chen, Xin
    Liuti Lixue Shiyan yu Celiang/Experiments and Measurements in Fluid Mechanics, 2000, 14 (01): : 90 - 95
  • [29] Flights of fancy in long-span design
    Solomon, NB
    ARCHITECTURAL RECORD, 2005, 193 (10) : 181 - +
  • [30] NEW APPROACHES TO LONG-SPAN STRUCTURES
    LEVY, M
    ARCHITECTURE-THE AIA JOURNAL, 1987, 76 (03): : 90 - 91