首页> 外文期刊>NEC Journal of Advanced Technology >A Behavior-Based Process Confinement Method and Its Application to a Server Security Solution 'StarDefence'
【24h】

A Behavior-Based Process Confinement Method and Its Application to a Server Security Solution 'StarDefence'

机译:基于行为的过程限制方法及其在服务器安全解决方案“ StarDefence”中的应用

获取原文
获取原文并翻译 | 示例
           

摘要

Conventional server applications such as Web applications usually perform their tasks through the collaboration of several processes including CGI processes and shell processes, etc. If any of the processes are taken over by attackers, the security of the entire applications could be compromised. To protect the server applications, it is necessary to protect all related processes. We propose a behavior-based process confinement method that restricts irregular process behavior. This method prevents the process behavior from violating given rules, called Context-Sensitive Policies (CSP). CSP's specify not only a set of system calls that each process is permitted to invoke, but also the relationship between system call sequences and application-dependent specifications, so that they can correctly describe the normal behavior of server applications. This paper describes a CSP matching algorithm with actual process events and how the algorithm efficiently prevents the processes from being taken over by attacks such as code injection. This paper also describes the implementation of this method and the result of its evaluation.
机译:诸如Web应用程序之类的常规服务器应用程序通常通过包括CGI进程和Shell进程等在内的多个进程的协作来执行其任务。如果攻击者接管了任何进程,则可能会损害整个应用程序的安全性。为了保护服务器应用程序,必须保护所有相关进程。我们提出了一种基于行为的过程限制方法,该方法可以限制不规则的过程行为。此方法可防止流程行为违反给定规则,即上下文敏感策略(CSP)。 CSP不仅指定允许每个进程调用的一组系统调用,而且还指定系统调用序列和与应用程序相关的规范之间的关系,以便它们可以正确描述服务器应用程序的正常行为。本文介绍了具有实际进程事件的CSP匹配算法,以及该算法如何有效地防止进程被诸如代码注入之类的攻击所接管。本文还介绍了该方法的实现及其评估结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号