The Experts below are selected from a list of 180 Experts worldwide ranked by ideXlab platform
Xinran Wang - One of the best experts on this subject based on the ideXlab platform.
-
ProtectingWebServicesfromRemoteExploitCode: A StaticAnalysisApproach
2020Co-Authors: Xinran WangAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation.
-
SigFree: A Signature-Free Buffer Overflow Attack Blocker
IEEE Transactions on Dependable and Secure Computing, 2010Co-Authors: Xinran WangAbstract:We propose SigFree, an online signature-free out-of-the-box application-layer method for blocking Code-Injection buffer overflow Attack messages targeting at various Internet services such as Web service. Motivated by the observation that buffer overflow Attacks typically contain executables whereas legitimate client requests never contain executables in most Internet services, SigFree blocks Attacks by detecting the presence of Code. Unlike the previous Code detection algorithms, SigFree uses a new data-flow analysis technique called Code abstraction that is generic, fast, and hard for exploit Code to evade. SigFree is signature free, thus it can block new and unknown buffer overflow Attacks; SigFree is also immunized from most Attack-side Code obfuscation methods. Since SigFree is a transparent deployment to the servers being protected, it is good for economical Internet-wide deployment with very low deployment and maintenance cost. We implemented and tested SigFree; our experimental study shows that the dependency-degree-based SigFree could block all types of Code-Injection Attack packets (above 750) tested in our experiments with very few false positives. Moreover, SigFree causes very small extra latency to normal client requests when some requests contain exploit Code.
-
WWW - Protecting web services from remote exploit Code: a static analysis approach
Proceeding of the 17th international conference on World Wide Web - WWW '08, 2008Co-Authors: Xinran WangAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation.
-
Protecting web services from remote exploit Code: a static analysis approach
WWW '08: Proceeding of the 17th international conference on World Wide Web, 2008Co-Authors: Xinran Wang, Yoon Chan Jhi, Sencun Zhu, Peng LiuAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation
Peng Liu - One of the best experts on this subject based on the ideXlab platform.
-
Protecting web services from remote exploit Code: a static analysis approach
WWW '08: Proceeding of the 17th international conference on World Wide Web, 2008Co-Authors: Xinran Wang, Yoon Chan Jhi, Sencun Zhu, Peng LiuAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation
J. Zimmermann - One of the best experts on this subject based on the ideXlab platform.
-
ACSAC - A framework for detecting network-based Code Injection Attacks targeting Windows and UNIX
21st Annual Computer Security Applications Conference (ACSAC'05), 2005Co-Authors: S. Andersson, A. Clark, G. Mohay, B. Schatz, J. ZimmermannAbstract:Code Injection vulnerabilities continue to prevail. Attacks of this kind such as stack buffer overflows and heap buffer overflows account for roughly half of the vulnerabilities discovered in software every year. The research presented in this paper extends earlier work in the area of Code Injection Attack detection in UNIX environments. It presents a framework for detecting new or previously unseen Code Injection Attacks in a heterogeneous networking environment and compares Code Injection Attack and detection strategies used in the UNIX and Windows environments. The approach presented is capable of detecting both obfuscated and clear text Attacks, and is suitable for implementation in the Windows environment. A prototype intrusion detection system (IDS) capable of detecting Code Injection Attacks, both clear text Attacks and obfuscated Attacks, which targets Windows systems is presented
-
A framework for detecting network-based Code Injection Attacks targeting Windows and UNIX
21st Annual Computer Security Applications Conference (ACSAC'05), 2005Co-Authors: S. Andersson, A. Clark, G. Mohay, B. Schatz, J. ZimmermannAbstract:Code Injection vulnerabilities continue to prevail. Attacks of this kind such as stack buffer overflows and heap buffer overflows account for roughly half of the vulnerabilities discovered in software every year. The research presented in this paper extends earlier work in the area of Code Injection Attack detection in UNIX environments. It presents a framework for detecting new or previously unseen Code Injection Attacks in a heterogeneous networking environment and compares Code Injection Attack and detection strategies used in the UNIX and Windows environments. The approach presented is capable of detecting both obfuscated and clear text Attacks, and is suitable for implementation in the Windows environment. A prototype intrusion detection system (IDS) capable of detecting Code Injection Attacks, both clear text Attacks and obfuscated Attacks, which targets Windows systems is presented
Yoon Chan Jhi - One of the best experts on this subject based on the ideXlab platform.
-
Protecting web services from remote exploit Code: a static analysis approach
WWW '08: Proceeding of the 17th international conference on World Wide Web, 2008Co-Authors: Xinran Wang, Yoon Chan Jhi, Sencun Zhu, Peng LiuAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation
Sencun Zhu - One of the best experts on this subject based on the ideXlab platform.
-
Protecting web services from remote exploit Code: a static analysis approach
WWW '08: Proceeding of the 17th international conference on World Wide Web, 2008Co-Authors: Xinran Wang, Yoon Chan Jhi, Sencun Zhu, Peng LiuAbstract:We propose STILL, a signature-free remote exploit binary Code Injection Attack blocker to protect web servers and web applications. STILL is robust to almost all anti-signature, anti-static-analysis and anti-emulation obfuscation