OTHER CALENDARSABOUT THE CALENDARMORE RESOURCES |
TRUST Security Seminar Series: Polymorphic Shellcode:The Demise of Signature-based Detection. Smashing the Stack with HydraSeminar | November 5 | 1-2 p.m. | Soda Hall, Wozniak Lounge Salvatore J. Stolfo, Department of Computer Science, Columbia University Team for Research in Ubiquitous Secure Technology Recent work on the analysis of polymorphic shellcode engines suggests that modern obfuscation methods would soon eliminate the usefulness of signature-based network intrusion detection methods and supports growing views that the new generation of shellcode cannot be accurately and efficiently represented by the string signatures which current IDS and AV scanners rely upon. We expand on this area of study by demonstrating several concepts in advanced shellcode polymorphism with a proof-of-concept engine which we call Hydra. Hydra distinguishes itself by integrating an array of obfuscation techniques, such as recursive NOP sleds and multi-layer ciphering into one system while offering multiple improvements upon existing strategies. In total, Hydra simultaneously attacks signature, statistical, disassembly, behavioral and emulation-based sensors, as well as frustrates offline forensics. This engine was developed to present an updated view of the frontier of modern polymorphic shellcode and provide an effective tool for evaluation of IDS systems, Cyber test ranges and other related security technologies. 510-643-5105 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
EECS Home | Contact WebTeam
Copyright © 2009 UC Regents
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||