Introducing reference flow control for detecting intrusion symptoms at the OS level

  • Authors:
  • Jacob Zimmermann;Ludovic Mé;Christophe Bidan

  • Affiliations:
  • Supélec, France;Supélec, France;Supélec, France

  • Venue:
  • RAID'02 Proceedings of the 5th international conference on Recent advances in intrusion detection
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents a novel approach to policy-based detection of "attacks by delegation". By exploiting unpredictable behaviour such as unknown side-effects, race-conditions, buffer overflows, confused deputies etc., these attacks aim at achieving their goals (i.e. executing some illegal operation) as legal consequences of other legitimate operations. The proposed approach enforces restrictions on whether an operation can be executed as a consequence of another, in order to detect that kind of attacks. We propose a proof-of-concept application to a Unix system and show its ability to detect novel attack scenarii that seek the same intrusion goals.