Skip to main content.

Berkeley Engineering

Educating Leaders. Creating Knowledge. Serving Society.

You are here:HomeEvents
Advanced search >
<< Back to previous page Print

<< Thursday, November 05, 2009 >>


TRUST Security Seminar Series: Polymorphic Shellcode:The Demise of Signature-based Detection. Smashing the Stack with Hydra

Seminar | November 5 | 1-2 p.m. | Soda Hall, Wozniak Lounge


Salvatore J. Stolfo, Department of Computer Science, Columbia University

Team for Research in Ubiquitous Secure Technology


Recent work on the analysis of polymorphic shellcode engines suggests that modern obfuscation methods would soon eliminate the usefulness of signature-based network intrusion detection methods and supports growing views that the new generation of shellcode cannot be accurately and efficiently represented by the string signatures which current IDS and AV scanners rely upon. We expand on this area of study by demonstrating several concepts in advanced shellcode polymorphism with a proof-of-concept engine which we call Hydra. Hydra distinguishes itself by integrating an array of obfuscation techniques, such as recursive NOP sleds and multi-layer ciphering into one system while offering multiple improvements upon existing strategies. In total, Hydra simultaneously attacks signature, statistical, disassembly, behavioral and emulation-based sensors, as well as frustrates offline forensics. This engine was developed to present an updated view of the frontier of modern polymorphic shellcode and provide an effective tool for evaluation of IDS systems, Cyber test ranges and other related security technologies.


510-643-5105