Automatic software instrumentation for the detection of non-control-data attacks

Jonathan Christofer Demay, Éric Totel, Frédéric Tronel

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

To detect intrusions resulting of an attack that corrupted data items used by a program to perform its computation, we propose an approach that automatically instruments programs to control a data-based behavior model during their execution. We build our model by discovering the sets of data the system calls depend on and which constraints these sets must verify at runtime. We have implemented our approach using a static analysis framework called Frama-C and we present the results of experimentations on a vulnerable version of OpenSSH.

Original languageEnglish
Title of host publicationRecent Advances in Intrusion Detection - 12th International Symposium, RAID 2009, Proceedings
PublisherSpringer Verlag
Pages348-349
Number of pages2
ISBN (Print)3642043410, 9783642043413
DOIs
Publication statusPublished - 1 Jan 2009
Externally publishedYes
Event12th International Symposium on Recent Advances in Intrusion Detection, RAID 2009 - Saint-Malo, France
Duration: 23 Sept 200925 Sept 2009

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5758 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference12th International Symposium on Recent Advances in Intrusion Detection, RAID 2009
Country/TerritoryFrance
CitySaint-Malo
Period23/09/0925/09/09

Fingerprint

Dive into the research topics of 'Automatic software instrumentation for the detection of non-control-data attacks'. Together they form a unique fingerprint.

Cite this