首页 | 本学科首页   官方微博 | 高级检索  
     

针对Shellcode变形规避的NIDS检测技术
引用本文:陈悦,薛质,王轶骏. 针对Shellcode变形规避的NIDS检测技术[J]. 信息安全与通信保密, 2007, 0(1): 99-103
作者姓名:陈悦  薛质  王轶骏
作者单位:上海交通大学信息安全学院,上海,200030
摘    要:现今,缓冲区溢出攻击仍是网络上最普遍和有效的攻击方式之一,常见于恶意攻击者的手动攻击以及病毒蠕虫的自发攻击。随着NIDS的发展,普通的缓冲区溢出攻击能够用基于Shellcode匹配的手段进行检测。然而,Shellcode变形技术的出现使缓冲区溢出攻击拥有了躲避NIDS检测的能力。论文在NIDS传统检测技术的基础上,详细研究了Shellcode的各种变形手段,提出了针对性的检测技术,并展望了未来的发展方向。

关 键 词:入侵检测  变形技术  规避技术
文章编号:1009-8054(2007)01-0099-05
修稿时间:2006-06-02

Apply NIDS Technology to Detect Polymorphic Shellcode Evading
Chen Yue,Xue Zhi,Wang Yijun. Apply NIDS Technology to Detect Polymorphic Shellcode Evading[J]. China Information Security, 2007, 0(1): 99-103
Authors:Chen Yue  Xue Zhi  Wang Yijun
Abstract:At present, buffer overflow still stands as one of the most prevalent and efficient way to attack network system. It usually results from manually attack by hackers and self-propagation attack by worms or viruses. With the development of NIDS, it is feasible to detect buffer overflow attack by simple Shellcode pattern-matching. However, the appearance of Shellcode polymorphism enables Shellcode to evade the detection of NIDS. This paper demonstrates a variety of detailed shellcode polymorphic technology against traditional IDS discerning method and presents new tech- nology and orientation to detect the polymorphic shellcode.
Keywords:Shellcode
本文献已被 CNKI 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号