Lecture Notes in Computer Science, 2002, Volume 2516/2002, 292-306, DOI: 10.1007/3-540-36084-0_16

Introducing Reference Flow Control for Detecting Intrusion Symptoms at the OS Level

Jacob Zimmermann, Ludovic Mé and Christophe Bidan

View Related Documents

Abstract

This paper presents a novel approach to policy-based detection of “attacks by delegation”. By exploiting unpredictable behaviour such as unknown side-effects, race-conditions, buffer overflows, confused deputies etc., these attacks aim at achieving their goals (i.e. executing some illegal operation) as legal consequences of other legitimate operations. The proposed approach enforces restrictions on whether an operation can be executed as a consequence of another, in order to detect that kind of attacks. We propose a proof-of-concept application to a Unix system and show its ability to detect novel attack scenarii that seek the same intrusion goals.

Fulltext Preview

Image of the first page of the fulltext document