Browse wiki

From Navigators

Jump to: navigation, search
Publication:Antunes10
Abstract The increasing reliance put on networked c The increasing reliance put on networked computer systems demands higher levels of dependability. This is even more relevant as new threats and forms of attack are constantly being revealed, compromising the security of systems. This paper addresses this problem by presenting an attack injection methodology for the automatic discovery of vulnerabilities in software components. The proposed methodology, implemented in AJECT, follows an approach similar to hackers and security analysts to discover vulnerabilities in network-connected servers. AJECT uses a specification of the server's communication protocol and predefined test case generation algorithms to automatically create a large number of attacks. Then, while it injects these attacks through the network, it monitors the execution of the server in the target system and the responses returned to the clients. The observation of an unexpected behavior suggests the presence of a vulnerability that was triggered by some particular attack (or group of attacks). This attack can then be used to reproduce the anomaly and to assist the removal of the error. To assess the usefulness of this approach, several attack injection campaigns were performed with 16 publicly available POP and IMAP servers. The results show that AJECT could effectively be used to locate vulnerabilities, even on well-known servers tested throughout the years. known servers tested throughout the years.
Author João Antunes + , Nuno Ferreira Neves + , Miguel Correia + , Paulo Verissimo + , Rui Neves +
Journal IEEE Transactions on Software Engineering, Special issue on Evaluation and Improvement of Software Dependability  +
Key Antunes10  +
Month jun  +
NumPubDate 2,010.06  +
Project Project:AJECT +
ResearchLine Fault And Intrusion Tolerance in Open Distributed Systems (FIT) +
Title Vulnerability Removal with Attack Injection  +
Type article  +
Url http://www.navigators.di.fc.ul.pt/archive/papers/IEEE-TSE10_Vulnerability_Removal_with_Attack_Injection.pdf  +
Year 2010  +
Categories Publication  +
Modification dateThis property is a special property in this wiki. 14 January 2013 14:40:57  +
hide properties that link here 
  No properties link to this page.
 

 

Enter the name of the page to start browsing from.
Views
Personal tools
Toolbox
Navigators toolbox