COOKIES: By using this website you agree that we can place Google Analytics Cookies on your device for performance monitoring. |
University of Cambridge > Talks.cam > Computer Laboratory Security Group meeting presentations > Polymorphic attacks against sequence-based software birthmarks
Polymorphic attacks against sequence-based software birthmarksAdd to your list(s) Download to your calendar using vCal
If you have a question about this talk, please contact Wei Ming Khoo. Sequence alignment algorithms have recently found a use in detecting code clones, software plagiarism, code theft, and polymorphic malware. This approach involves extracting birthmarks, in this case sequences, from programs and comparing them using sequence alignment, a procedure which has been intensively studied in the field of bioinformatics. This idea seems promising. However, we show that an attacker can evade detection by considering the positions of inserted dummy code and/or the frequency of function calls. Moreover, we found that randomly inserting and deleting symbols in the sequence was ineffective. By using birthmark sequences extracted from actual malicious and benign programs, we found that the most effective strategy was to use a hybrid approach incorporating “non-consecutive insertion” and “highest frequency deletion”. We also discuss the implementation costs of such attacks and propose using non-determinism through concurrent programming as an alternative evasion strategy. This is joint work with Hyoungshick Kim and Pietro Lio’. This is a practice talk for SSP ’12. This talk is part of the Computer Laboratory Security Group meeting presentations series. This talk is included in these lists:
Note that ex-directory lists are not shown. |
Other listsWhat IS the deal with meat? Open Research Cambridge Enterprise Tuesday 2016-2017Other talksThe frequency of ‘America’ in America Oncological imaging: introduction and non-radionuclide techniques Sneks long balus Borel Local Lemma Bears, Bulls and Boers: Market Making and Southern African Mining Finance, 1894-1899 What is the Market Potential of Multilingualism? Structural basis for human mitochondrial DNA replication, repair and antiviral drug toxicity TBC "The integrated stress response – a double edged sword in skeletal development and disease" Scale and anisotropic effects in necking of metallic tensile specimens Crowding and the disruptive effect of clutter throughout the visual system Climate change, species' abundance changes and protected areas |