Intrusion Detection Systems (IDSs) are widely deployed with increasing of unauthorized activities and attacks. However they often overload security managers by triggering thousands of alerts per day. And up to 99% of these alerts are false positives (i.e. alerts that are triggered incorrectly by benign events). This makes it extremely difficult for managers to correctly analyze security state and react to attacks. In this chapter the authors describe a novel system for reducing false positives in intrusion detection, which is called ODARM (an Outlier Detection-Based Alert Reduction Model). Their model based on a new data mining technique, outlier detection that needs no labeled training data, no domain knowledge and little human assistance. The main idea of their method is using frequent attribute values mined from historical alerts as the features of false positives, and then filtering false alerts by the score calculated based on these features. In order to filter alerts in real time, they also design a two-phrase framework that consists of the learning phrase and the online filtering phrase. Now they have finished the prototype implementation of our model. And through the experiments on DARPA 2000, they have proved that their model can effectively reduce false positives in IDS alerts. And on real-world dataset, their model has even higher reduction rate.
since sensor nodes have limited energy resources, prolonging network lifetime and improving capability are essential elements in energy-efficient Wireless Sensor Networks (WSNs). Most existing approaches consider the residual energy of a single node when electing a cluster head (CH), omitting other factors associated with the node, thus, this paper proposes a new scheme energy-based clustering model (EBCM) for WSNs to reduce the overall energy consumption, balance the energy consumption among all nodes and improve the network stability. Based on the LEACH, EBCM take into consideration node's current energy and degree in clustering process, the study has examined the performance of the proposed EBCM algorithm using simulation experiments. We compare the performance of our EBCM against some counterparts. The results demonstrate that our algorithm outperforms its counterparts in terms of energy efficiency and stability.
在无线传感器与执行器网络中,可以通过调整剩余节点的位置来提高目标区域覆盖率,以更好地为sensor节点服务。提出了一种基于二分编码的网络移动覆盖算法(SMR算法)。在每次搜索中,试探性地调整失效节点区域的临近执行器节点位置来寻找最佳位置,重复此搜索过程直到覆盖数不再增加,以实现近似的局部最优覆盖。本算法提高了剩余节点的覆盖率,减少了执行器节点移动的消耗,与已有算法相比也表现出了较好的性能。
This paper aims at finding an algorithm in wireless sensor and actor networks (WSANs) to recover the failure actor. First, this paper describes the real-time coverage model in WSANs, proves WSAN's coverage recovery is NP-hard. A cell-based mobile fault-tolerant algorithm HMFR is presented to recover the failure actor, which has a good performance under a limited condition of initial deployment of network. Through simulation experiments, the results show that the algorithm is more effective than the present algorithms in terms of actor coverage and move distance.
Web based malware infection and propagation method becomes the main way of virus's spreading in the Internet. Drive-by Download is one of the best known ways among them. Make use of the browser extension to monitor user's download file activities,to construct the white list. In addition to this,install a hook in the kernel space to prevent unauthorized file to execute,so as to block the Drive-by Download attacks. It has implemented a prototype:DPrevent (Drive-by Download Prevent),which is based on the Firefox ex-tension,for the Microsoft Windows platform. The experiment demonstrates that,the false positive and false negative of the DPrevent are both zero. Since of the agnostic for the attack method,it can also defend the zero-day attacks. The overhead of DPrevent is almost zero, which is better than the other dynamic skills in this area.
Kernel rootkit has been demonstrated as a serious operating system kernel threat.With the injection of the malicious rootkit into OS kernel,which tampers vital data structures,the intruder can deliver process hiding,log file deletion,privacy information stealing and othermalicious behaviors.Based on the basic insight of that rootkit interferes in OS kernel through data structures,in this paper,we present a compiler-based data structure randomization technique,which can identify the randomiz ability and achieve the randomization automatically withoutaltering the original semantics.With the random and unexpected data structure field sequence,the intrusion of kernel rootkit will fail.Through the experiments of eight well-known variousrootkits in five categories,we present that our approach is effective with almost zero overload.
针对WSANs中的服务发现问题,提出了一种基于六边形分区的多中心编址服务发现算法MASD。算法综合考虑了节点的通信开销和存储负担,设计了一种多中心的编址方案,此方案采用局部计算,拥有计算量小的优点。Sensor节点可按地址或者采用局部搜索的算法寻找到达附近actor节点的下一跳节点。通过实验发现,与现有的imesh算法相比,本算法具有更短的搜索距离和更少的通信开销。
Return-Oriented Programming (ROP)is a technique which leverages the instructionsnippets in existing libraries/executables to construct Turing Complete programs.Such techniquecan generate the shellcode which evades most code injection defenses.However,ROP attack isusually composed with gadgets which are ending in ret instruction without the corresponding callinstruction.Based on this fact,several defense mechanisms have been proposed to detect theROP malicious code.In this paper,we present Branch Instruction-Oriented Programming(BIOP)attack which uses the gadgets ending in jmp instruction or call instruction.This newtechnique,which uses jmp instruction or call instruction to replace the ret instruction,breaks thehypothesis of existing defense tools.Meanwhile we propose a tool to automatically construct thereal-world BIOP attack,which as demonstrated in our experiment can bypass most of the exiting ROP defenses.
Recently smartphones and mobile devices have gained incredible popularity for their vibrant feature-rich applications (or apps). Because it is easy to repackage Android apps, software plagiarism has become a serious problem. In this paper, we present an accurate and robust system DroidSim to detect code reuse. DroidSim calculates similarity score only with component-based control flow graph (CB-CFG). CB-CFG is a graph of which nodes are Android APIs and edges represent control flow precedence order in each Android component. Our system can be applied to detect repackaged apps and malware variants. We evaluate DroidSim on 121 apps and 706 malware variants. The results show that our system has no false negative and a false positive of 0.83% for repackaged apps, and a detection ratio of 96.60% for malware variants. Besides, ADAM is used to obfuscate apps and the result reveals that ADAM has no influence on our system.
The locations of sensor nodes are very important to many wireless sensor networks (WSNs). When WSNs are deployed in hostile environments, two issues about sensors’ locations need to be considered. First, attackers may attack the localization process to make estimated locations incorrect. Second, since sensor nodes may be compromised, the base station (BS) may not trust the locations reported by sensor nodes. Researchers have proposed two techniques, secure localization and location verification, to solve these two issues, respectively. In this paper, we present a survey of current work on both secure localization and location verification. We first describe the attacks against localization and location verification, and then we classify and describe existing solutions. We also implement typical secure localization algorithms of one popular category and study their performance by simulations.
移动Ad hoc 网自组织、移动性等特性为组网带来便利的同时也增加了路由管理的难度.针对现有可靠路由算法解决问题具有局限性以及获取链路评价信息低效等问题,在DSR(dynamic source routing)协议基础上提出了基于本地信任系统的可靠路由协议(reliable routing protocol based on local trust system,简称TR-DSR).TR-DSR 协议选择路由时,综合考虑路由上各节点和各链路的可靠信任度,并在路由建立过程中利用这些信息,在确保找到可靠路由的基础上降低寻路开销.同时,为了防止自私节点对信任系统评价正确性的影响,提出了基于GTFT(generous tit fortat)策略的激励节点推荐响应行为的DFR(decide forwarding recommendation)算法.仿真实验结果表明,在节点频繁移动和存在大量自私节点的网络中,该协议的性能优势明显,验证了TR-DSR 协议的可靠性.;The features of mobile ad hoc network such as self-organization, mobility bring the convenience of network, but also increase the difficulty of routing management. To solve the limits of the existing reliable route protocol and its inefficient access to link information, according to DSR (dynamic source routing) protocol, a reliable routing protocol based on local trust system (TR-DSR) is proposed. TR-DSR completely considers and uses the reliability of each node and each link to find reliable routes. Moreover, the system also reduces overhead routing during this process. Meanwhile, to reduce the impact of selfish nodes to improve the correctness of the trust system, the DFR (decide forwarding recommendation) algorithm based on GTFT (generous tit for tat) strategy which motivates response to recommendation requests, is provided. Simulation results indicate that in more challenging situations of high mobility and selfish nodes, TR-DSR can improve the performance significantly and prove the reliability of TR-DSR.
Since smartphones have stored diverse sensitive privacy information, including credit card and so on, a great deal of malware are desired to tamper them. As one of the most prevalent platforms, Android contains sensitive resources that can only be accessed via corresponding APIs, and the APIs can be invoked only when user has authorized permissions in the Android permission model. However, a novel threat called privilege escalation attack may bypass this watchdog. It's presented as that an application with less permissions can access sensitive resources through public interfaces of a more privileged application, which is especially useful for malware to hide sensitive functions by dispersing them into multiple programs. We explore privilege-escalation malware evolution techniques on samples from Android Malware Genome Project. And they have showed great effectiveness against a set of powerful antivirus tools provided by VirusTotal. The detection ratios present different and distinguished reduction, compared to an average 61% detection ratio before transformation. In order to conquer this threat model, we have developed a tool called DroidAlarm to conduct a full-spectrum analysis for identifying potential capability leaks and present concrete capability leak paths by static analysis on Android applications. And we can still alarm all these cases by exposing capability leak paths in them.
In the Three-dimensional Network on Chip(3D?NoC) design,the pros of the communication mechanism between the layers will affect the performance of the entire 3D NoC system.In order to solve the above problem,this paper makes some improvements based on the traditional three-dimensional interconnect.For 3D NoC communication problems,this paper proposes a low hardware resource consumption,high performance bus architecture under GEMS simulation platform.It improves routing design,and bus-based 3D NoC router.Experimental results show that the architecture can increase speed-up ratio of common algorithms,and improve overall system performance.
在无线传感器/执行器网络(WSAN)中,移动执行器(actor)节点之间需要通过协商进行任务分配来响应产生的服务请求,其目标是尽可能减少协商时的通信开销和对事件的响应时间。现有的解决方案中,基于市场竞拍的分布式简单竞拍聚合协议(SAAP)比较适合资源受限的WSAN网络。在SAAP的基础上提出了一种定向的竞拍聚合协议DSAAP,该协议根据方向信息对下一跳子节点进行筛选,同时限制回传的信息,以减少竞拍过程中的消息转发。通过实验与现有的SAAP进行比较,发现该协议在最优节点发现率和选出节点与最优节点距离比这两个参数性能不降低的前提下降低了通信开销。
移动Ad hoc网自组织、移动性等特性为组网带来便利的同时也增加了路由管理的难度.针对现有可靠路由算法解决问题具有局限性以及获取链路评价信息低效等问题,在DSR(dynamic source routing)协议基础上提出了基于本地信任系统的可靠路由协议(reliable routing protocol based on local trust system,简称TR-DSR).TR-DSR协议选择路由时,综合考虑路由上各节点和各链路的可靠信任度,并在路由建立过程中利用这些信息,在确保找到可靠路由的基础上降低寻路开销.同时,为了防止自私节点对信任系统评价正确性的影响,提出了基于GTFT(generous tit for tat)策略的激励节点推荐响应行为的DFR(decide forwarding recommendation)算法.仿真实验结果表明,在节点频繁移动和存在大量自私节点的网络中,该协议的性能优势明显,验证了TR-DSR协议的可靠性.
Return-oriented Programming(ROP) is a new attack based on code-reuse technique.This paper proposes a dynamic runtime detection system for return-oriented programming attack,studies the intrinsic nature of ROP and its variant.According to these nature,it designs ret integrity checking,call integrity checking and jmp integrity checking.The detecting system is implemented to static instrument and dynamic run-time checking.Static instrument assemble the analysis code into the program to be detected and dynamic run-time checking do the real detection with the three integrity checking.Preliminary experimental results show that the method can efficiently detect ROP malicious code and have no false positives and negatives.
Virtualization plays a key role in constructing cloud environments and providing services. Although the main jobs of the hypervisors are to guarantee proper isolation between domains and provide them services, the hypercall interface provided by the hypervisor for cross-layer interactions with domains gives attackers the possibility to breach the isolation or cause denial of service from inside the domains. In this paper, we propose a transparent approach that uses randomization technique to protect the hypercall interface. In our approach, even facing a total compromise of a domain, the security of the virtualization platforms can be guaranteed. We have built a prototype called RandHyp based on Xen. Our experimental results show that RandHyp can effectively prevent attacks via Xen hypercall interface with a small overhead.
Metamorphism and polymorphism are often applied on some malwares to protect their programs against reverse engineering or detected by some anti virus products. However, data structure information based malware signatures invalidate traditional metamorphic technologies. In this paper, we propose a metamorphism tool, which obfuscates data structure in binary code level. This obfuscation technology is more flexible compared to the previous randomizations. Preliminary experimental results show that our tool could obfuscate data structure remarkably with little performance overhead.
Recent years have witnessed a growing interest in applications of wireless sensor and actor networks (WSANs). In WSANs, maintaining interactor connectivity is of vital concern in order to reach application level. Failure of a critical actor may partition the inter-actor network into disjoint segments. This paper proposed an application-oriented fault detection and recovery algorithm (AFDR), a novel distributed algorithm to reestablish connectivity. AFDR identifies critical actors and designates backups for them. A backup actor detects the critical node failure and initiates a recovery process via moving to the optimal position. The purpose of AFDR is to satisfy application requirements, reduce recovery overhead, and limit the impact of critical node failure on coverage and connectivity to the utmost. The effectiveness of AFDR is validated through simulation experiments.