The Experts below are selected from a list of 180 Experts worldwide ranked by ideXlab platform

Xinran Wang - One of the best experts on this subject based on the ideXlab platform.

  • ProtectingWebServicesfromRemoteExploitCode: A StaticAnalysisApproach
    2020
    Co-Authors: Xinran Wang
    Abstract:

    We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation.

  • SigFree: A Signature-Free Buffer Overflow Attack Blocker
    IEEE Transactions on Dependable and Secure Computing, 2010
    Co-Authors: Xinran Wang
    Abstract:

    We propose SigFree, an online signature-free out-of-the-box application-layer method for blocking Code-Injection buffer overflow Attack messages targeting at various Internet services such as Web service. Motivated by the observation that buffer overflow Attacks typically contain executables whereas legitimate client requests never contain executables in most Internet services, SigFree blocks Attacks by detecting the presence of Code. Unlike the previous Code detection algorithms, SigFree uses a new data-flow analysis technique called Code abstraction that is generic, fast, and hard for exploit Code to evade. SigFree is signature free, thus it can block new and unknown buffer overflow Attacks; SigFree is also immunized from most Attack-side Code obfuscation methods. Since SigFree is a transparent deployment to the servers being protected, it is good for economical Internet-wide deployment with very low deployment and maintenance cost. We implemented and tested SigFree; our experimental study shows that the dependency-degree-based SigFree could block all types of Code-Injection Attack packets (above 750) tested in our experiments with very few false positives. Moreover, SigFree causes very small extra latency to normal client requests when some requests contain exploit Code.

  • WWW - Protecting web services from remote exploit Code: a static analysis approach
    Proceeding of the 17th international conference on World Wide Web - WWW '08, 2008
    Co-Authors: Xinran Wang
    Abstract:

    We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation.

  • Protecting web services from remote exploit Code: a static analysis approach
    WWW '08: Proceeding of the 17th international conference on World Wide Web, 2008
    Co-Authors: Xinran Wang, Yoon Chan Jhi, Sencun Zhu, Peng Liu
    Abstract:

    We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation

Peng Liu - One of the best experts on this subject based on the ideXlab platform.

J. Zimmermann - One of the best experts on this subject based on the ideXlab platform.

  • ACSAC - A framework for detecting network-based Code Injection Attacks targeting Windows and UNIX
    21st Annual Computer Security Applications Conference (ACSAC'05), 2005
    Co-Authors: S. Andersson, A. Clark, G. Mohay, B. Schatz, J. Zimmermann
    Abstract:

    Code Injection vulnerabilities continue to prevail. Attacks of this kind such as stack buffer overflows and heap buffer overflows account for roughly half of the vulnerabilities discovered in software every year. The research presented in this paper extends earlier work in the area of Code Injection Attack detection in UNIX environments. It presents a framework for detecting new or previously unseen Code Injection Attacks in a heterogeneous networking environment and compares Code Injection Attack and detection strategies used in the UNIX and Windows environments. The approach presented is capable of detecting both obfuscated and clear text Attacks, and is suitable for implementation in the Windows environment. A prototype intrusion detection system (IDS) capable of detecting Code Injection Attacks, both clear text Attacks and obfuscated Attacks, which targets Windows systems is presented

  • A framework for detecting network-based Code Injection Attacks targeting Windows and UNIX
    21st Annual Computer Security Applications Conference (ACSAC'05), 2005
    Co-Authors: S. Andersson, A. Clark, G. Mohay, B. Schatz, J. Zimmermann
    Abstract:

    Code Injection vulnerabilities continue to prevail. Attacks of this kind such as stack buffer overflows and heap buffer overflows account for roughly half of the vulnerabilities discovered in software every year. The research presented in this paper extends earlier work in the area of Code Injection Attack detection in UNIX environments. It presents a framework for detecting new or previously unseen Code Injection Attacks in a heterogeneous networking environment and compares Code Injection Attack and detection strategies used in the UNIX and Windows environments. The approach presented is capable of detecting both obfuscated and clear text Attacks, and is suitable for implementation in the Windows environment. A prototype intrusion detection system (IDS) capable of detecting Code Injection Attacks, both clear text Attacks and obfuscated Attacks, which targets Windows systems is presented

Yoon Chan Jhi - One of the best experts on this subject based on the ideXlab platform.

Sencun Zhu - One of the best experts on this subject based on the ideXlab platform.