loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
20th Annual Computer Security Applications Conference (ACSAC'04)
Detecting Attacks That Exploit Application-Logic Errors Through Application-Level Auditing
Tucson, Arizona
December 06-December 10
ISBN: 0-7695-2252-1
Jingyu Zhou, University of California, Santa Barbara
Giovanni Vigna, University of California, Santa Barbara
Host security is achieved by securing both the operating system kernel and the privileged applications that run on top of it. Application-level bugs are more frequent than kernel-level bugs, and, therefore, applications are often the means to compromise the security of a system. Detecting these attacks can be difficult, especially in the case of attacks that exploit application-logic errors. These attacks seldom exhibit characterizing patterns as in the case of buffer overflows and format string attacks. In addition, the data used by intrusion detection systems is either too low-level, as in the case of system calls, or incomplete, as in the case of syslog entries. This paper presents a technique to enforce non-bypassable, application-level auditing that does not require the recompilation of legacy systems. The technique is implemented as a kernel-level component, a privileged daemon, and an off-line language tool. The technique uses binary rewriting to instrument applications so that meaningful and complete audit information can be extracted. This information is then matched against application-specific signatures to detect attacks that exploit application-logic errors. The technique has been successfully applied to detect attacks against widely-deployed applications, including the Apache web server and the OpenSSH server.
Citation:
Jingyu Zhou, Giovanni Vigna, "Detecting Attacks That Exploit Application-Logic Errors Through Application-Level Auditing," acsac, pp.168-178, 20th Annual Computer Security Applications Conference (ACSAC'04), 2004
Usage of this product signifies your acceptance of the Terms of Use.