Generating profile-based signatures for online intrusion and failure detection

dc.contributor.authorMasri, Wes
dc.contributor.authorAbou-Assi, Rawad Abu
dc.contributor.authorel-Ghali, Marwa
dc.contributor.departmentDepartment of Electrical and Computer Engineering
dc.contributor.departmentDepartment of Computer Science
dc.contributor.facultyMaroun Semaan Faculty of Engineering and Architecture (MSFEA)
dc.contributor.facultyFaculty of Arts and Sciences (FAS)
dc.contributor.institutionAmerican University of Beirut
dc.date.accessioned2025-01-24T11:29:08Z
dc.date.available2025-01-24T11:29:08Z
dc.date.issued2014
dc.description.abstractContext Program execution profiles have been extensively and successfully used in several dynamic analysis fields such as software testing and fault localization. Objective This paper presents a pattern-matching approach implemented as an application-based intrusion (and failure) detection system that operates on signatures generated from execution profiles. Such signatures are not descriptions of exploits, i.e. they do not depend on the syntax or semantics of the exploits, but instead are descriptions of program events that correlate with the exploitation of program vulnerabilities. Method A vulnerability exploit is generally correlated with the execution of a combination of program elements, such as statements, branches, and definition-use pairs. In this work we first analyze the execution profiles of a vulnerable application in order to identify such suspicious combinations, define signatures that describe them, and consequently deploy these signatures within an intrusion detection system that performs online signature matching. Results To evaluate our approach, which is also applicable to online failure detection, we implemented it for the Java platform and applied it onto seven open-source applications containing 30 vulnerabilities/defects for the purpose of the online detection of attacks/ failures. Our results showed that our approach worked very well for 26 vulnerabilities/defects (86.67%) and the overhead imposed by the system is somewhat acceptable as it varied from 46% to 102%. The exhibited average rates of false negatives and false positives were 0.43% and 1.03%, respectively. Conclusion Using profile-based signatures for online intrusion and failure detection was shown to be effective. © 2013 Elsevier B.V. All rights reserved.
dc.identifier.doihttps://doi.org/10.1016/j.infsof.2013.09.004
dc.identifier.eid2-s2.0-84889882586
dc.identifier.urihttp://hdl.handle.net/10938/27093
dc.language.isoen
dc.relation.ispartofInformation and Software Technology
dc.sourceScopus
dc.subjectApplication-based intrusion detection
dc.subjectCombinations of program elements
dc.subjectGenetic algorithm
dc.subjectOnline failure detection
dc.subjectProfile-based signatures
dc.subjectVulnerability-based signatures
dc.subjectApplication programs
dc.subjectGenetic algorithms
dc.subjectIntrusion detection
dc.subjectSemantics
dc.subjectSoftware testing
dc.subjectFault localization
dc.subjectIntrusion detection systems
dc.subjectOnline failure detections
dc.subjectProgram elements
dc.subjectProgram execution profile
dc.subjectProgram vulnerability
dc.subjectJava programming language
dc.titleGenerating profile-based signatures for online intrusion and failure detection
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2014-10643.pdf
Size:
775.91 KB
Format:
Adobe Portable Document Format