Dynamic emulation based modeling and detection of polymorphic shellcode at the network level

来源 :Science in China(Series F:Information Sciences) | 被引量 : 0次 | 上传用户:SANTACRUZ1
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
It is a promising way to detect polymorphic shellcode using emulation method. However,previous emulation-based approaches are limited in their performance and resilience against evasions. A new enhanced emulation-based detection approach is proposed,including an automaton-based model of the dynamic behavior of polymorphic shellcode and a detection algorithm,the detection criterion of which is derived from that model and ensures high detection accuracy. The algorithm also contains several optimization techniques,highly improving the running performance and the resilience against detection evasion shellcode. We have implemented a prototype system for our approach. The advantages of our algorithm are validated by the experiments with real network data,polymorphic shellcode samples generated by available polymorphic engines and hand-crafted detection evasion shellcode. It is a promising way to detect polymorphic shellcode using emulation method. However, previous emulation-based approaches are limited in their performance and resilience against evasions. A new enhanced emulation-based detection approach is proposed, including an automaton-based model of the dynamic behavior of polymorphic shellcode and a detection algorithm, the detection criterion of which is derived from that model and ensures high detection accuracy. The algorithm also contains several optimization techniques, highly improving the running performance and the resilience against detection evasion shellcode. We have implemented a prototype systems for our approach. The advantages of our algorithm are validated by the experiments with real network data, polymorphic shellcode samples generated by available polymorphic engines and hand-crafted detection evasion shellcode.
The disposition of most drugs is highly dependent on specialized transporters.OAT1 and OAT3 are two organic anion transporters expressed in the basolateral memb
Objective: To assess if arachnoid cells have the capability to present antigen and activate T-lymphocytes after stimulation by bloody cerebrospinal fluid (CSF),
目的为难治性癫(IE)患者的外科治疗制定循证方案。方法针对1例IE患者诊治中的临床问题,检索临床指南、系统评价、m eta分析及随机对照试验,并评价其质量,判断其真实性、适
啊哈!又在“淘宝网”上寻到宝贝了!快用“支付宝”买下来。到网上银行看看这个月的工资发了没有,赶紧把信用卡的欠款给还了……使用方便快捷的网上银行已经成了我们日常生活中再平常不过的一件事,可是不少人仍然担心安全问题。怎么办?别再杞人忧天了,赶紧申请一个“数字证书”吧。    数字证书,  你的互联网“身份证”    你到银行柜台开户和取款时,银行一般都会要求你出示身份证,这是为了识别你的身份而保证款项