跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.127) 您好!臺灣時間:2026/07/30 13:22
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:許明淵
研究生(外文):Ming-Yuan Hsu
論文名稱:具變形躲避偵測機制穿透測試載具
論文名稱(外文):Penetration Testing Approach by Mutating Sled of Exploit
指導教授:楊明豪羅嘉寧羅嘉寧引用關係
指導教授(外文):Ming-Hour YangJia-Ning Luo
學位類別:碩士
校院名稱:中原大學
系所名稱:資訊工程研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2008
畢業學年度:96
語文別:中文
論文頁數:34
中文關鍵詞:滑動區段穿透測試入侵偵測系統變形蟲shellcode
外文關鍵詞:sledIDSshellcodepolymorphismpenetration test
相關次數:
  • 被引用被引用:0
  • 點閱點閱:211
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
由於蠕蟲可利用來快速擴散攻擊的目標,若是蠕蟲載送惡意程式碼且利用加密的手法來躲過入侵偵測系統(IDS),則會對現今之網路防護體系造成莫大之傷害,而以往蠕蟲的Shellcode是IDS做為判別確認是否為網路攻擊的主要特徵,而因此攻擊者為了躲避偵測,會將Shellcode透過簡單的加密以達到躲避的效果,也就是一般所稱的變形蟲。
為了防範變形蟲,我們首先要研究變形蟲是否有變化的可能性能夠躲過現有之IDS偵測機制,因此我們在本論文中探討並利用加密機制和多元的解密器來測試現有之特徵辨識IDS Snort是否可以正常偵測到我們的穿透測試載具,以及我們提出改變蠕蟲中的滑動區段必須能夠從任一位元組開始執行並正常的執行到Shellcode之特性以及調整OP code分佈使得一些分析可執行碼之IDS 如STRIDE、APE是否可成功偵測我們所產生之變形蟲。
我們並於實驗室中利用所蒐集之Sasser、Blaster蠕蟲為基底進行變形、並加入正常之背景流量於我們的實驗環境中,對Snort和STRIDE進行比對測試。發現能夠成功的躲過入侵偵測系統,並將測試程式利用我們的載具攜帶至目的端電腦,而有9成以上的機率成功進行擴散。
A worm is usually used to speedy spread the exploit code to host in the internet, and if it utilizing the encrypting technique, would causes the serious disasters. Since the traditional IDS are not able to detect the shellcode of the encrypted polymorphic worm.
For against the polymorphic worm, we need to research how the polymorphism could mutate to evade the current detection mechanism. In this paper, we analyses and used the encryption and polymorphic decoder to test whether the IDS Snort, a signature-based IDS could detect out penetration testing tool or not. We propose a scheme to mutate the signature of a worm, to let any byte in sled and shellcode of the worm could be executed normally on destination to evade the IDSs like STRIDE or APE.
Finally, we use Sasser and Blaster worms as examples to blend into normal traffic in our experiment and emulate a penetration test to IDSs, Snort and STRIDE. According to the emulation results, our penetration testing tool could be successful possess the exploit code and evading the IDS to the end host above 90%.
摘要 I
ABSTRACT II
目錄 III
圖目錄 IV
表目錄 V
1 前言 1
2 相關研究 4
3 隨機金鑰穿透測試載具 7
3.1 設置蠕蟲滑動區段 10
3.1.1 產生靜態隨機滑動區段 11
3.1.2 產生動態滑動區段 13
3.2 躲避偵測機制 16
3.3 填充區段 19
4 實驗及分析結果 20
4.1. 實驗環境 20
4.2. 躲避偵測 21
4.3. 頻譜分析 24
5 結論 27
6 參考文獻 28

圖目錄
圖1:蠕蟲架構圖 2
圖2:變形蟲架構圖 3
圖3:ONE-BYTE NOP EQUIVALENTS SLED 5
圖4:MULTI-BYTE NOP EQUIVALENTS SLED 5
圖5:OBFUSCATED TRAMPOLINE SLED 6
圖6:STRIDE的偵測執行步驟 6
圖7:隨機金鑰穿透測試載具變形流程圖 8
圖8:STASLD以INTEL指令集組成滑動區段範例 13
圖9:正常封包與滑動區段頻譜分析、比較圖 15
圖10:DNYSLD設置滑動區段範例 16
圖11:躲避偵測範例 17
圖12:POS的選擇方式 18
圖13:DYNSLD結果頻譜分析圖 19
圖14:填充區段的設置結果分析圖 20
圖15:實驗的環境平台架構圖 21
圖16:偵測流程圖 22
圖17:頻譜分析各位元組統計結果 25
圖18:頻譜分析各位元組差異程度 27

表目錄
表格1:穿透IDS測試實驗 22
表格2:SNORT偵測SASSER特徵碼 23
表格3:變形測試碼穿透STRIDE成功率 24
[1]R. Sommer and V. Paxson, "Enhancing byte-level network intrusion detection signatures with context," Proceedings of the 10th ACM conference on Computer and communications security, pp. 262-271, 2003.
[2]C. Krugel, T. Toth, and E. Kirda, Service specific anomaly detection for network intrusion detection: ACM Press New York, NY, USA, 2002.
[3]M. Roesch, "Snort-Lightweight Intrusion Detection for Networks," Proceedings of the 1999 USENIX LISA Systems Administration Conference, 1999.
[4]D. M. Kinzle and M. C. Elder, "Internet WORMS: past, present, and future: Recent worms: a survey and trends," Proceedings of the 2003 ACM workshop on Rapid Malcode, ACM, pp. 1-10, 2003.
[5]C. C. Zou, L. Gao, W. Gong, and D. Towsley, "Monitoring and early warning for internet worms," Proceedings of the 10th ACM conference on Computer and communication security, pp. 190-199, 2003.
[6]D. Moore and C. Shannon, "Code-Red: a case study on the spread and victims of an internet worm," Proceedings of the second ACM SIGCOMM Workshop on Internet measurment, pp. 273-284, 2002.
[7]D. Moore, V. Paxson, S. Savage, C. Shannon, S. Staniford, and N. Weaver, "The Spread of the Sapphire/Slammer Worm," IEEE Security and Privacy, July 2003.
[8]P. Akritidis, E. P. Markatos, M. Polychronakis, and K. Anagnostakis, "Stride: Polymorphic sled detection through instruction sequence analysis," 20th IFIP International Information Security Conference, 2005.
[9]C. Team, "Polymorphic shellcode engine using spectrum analysis," Phrack Magazine, vol. 11, p. 9, 2003.
[10]K2, "ADMmutate," http://www.ktwo.ca/ADMmutate-0.8.4.tar.gz.
[11]T. Toth and C. Kruegel, "Accurate buffer overflow detection via abstract payload execution," Proceedings of the, vol. 5, pp. 274–291.
[12]P. Szor and P. Ferrie, "HUNTING FOR METAMORPHIC," VIRUS, vol. 123, 2001.
[13]C. Kaufman, R. Perlman, and M. Speciner, Network security: private communication in a public world: Prentice-Hall, Inc. Upper Saddle River, NJ, USA, 1995.
[14]O. Kolesnikov and W. Lee, "Advanced Polymorphic Worms: Evading IDS by Blending in with Normal Traffic," USENIX Security Symposium, 2006.
[15]P. Jungck, S. S. Y. Shim, and C. S. Technologies, "Issues in high-speed Internet security," IEEE Computer, vol. 37, pp. 36-42, 2004.
[16]M. D. Team, "Metasploit Project, 2006," http://www.metasploit.com/.
[17]L. Julus, "Polymorphism Tutorial Part II v1.0 Advanced Approach ", http://vx.netlux.org/lib/static/vdat/tupolyii.htm, 1998.
[18]P. Fogla and W. Lee, "Evading network anomaly detection systems: formal reasoning and practical techniques," Proceedings of the 13th ACM conference on Computer and communications security, pp. 59-68, 2006.
[19]K. Wang and S. J. Stolfo, "Anomalous Payload-Based Network Intrusion Detection," Recent Advances In Intrusion Detection: 7th International Symposium, RAID 2004, Sophia Antipolis, France, September 15-17, 2004: Proceedings, 2004.
[20]J. B. Kruskal Jr, "On the Shortest Spanning Subtree of a Graph and the Traveling Salesman Problem," Proceedings of the American Mathematical Society, vol. 7, pp. 48-50, 1956.
[21]K. S. Gatlin, "Windows data alignment on IPF, x86, and x86-64, Feb. 2003. MSDN Library," http://msdn.microsoft.com/.
[22]M. Bailey, E. Cooke, F. Jahanian, D. Watson, and J. Nazario, "The Blaster Worm: Then and Now," IEEE SECURITY & PRIVACY, pp. 26-31, 2005.
[23]C. A. Ca, "20 W32/Blaster worm," CERT/CC, 2003.
電子全文 電子全文(本篇電子全文限研究生所屬學校校內系統及IP範圍內開放)
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top