Sky-walker: an integrated solution for network and computer security

Tzi‐cker Chiueh, Fu‐Hau Hsu · 2004

In this dissertation, we propose several distinct approaches to deal with different security threats and we also provide an infrastructure, sky-walker, to integrate them. Based on the sky-walker infrastructure, we will show how different powerful solutions for different security threats, such as Honeypot, anti-buffer overflow attacks, anti-port-scanning, anti-OS fingerprinting, and anti-TCP hijacking, could be combined together efficiently and effectively. Sky-walker's constituent components fall into 3 classes, RAD, PICA, and CTCP The end host site component, RAD, is a patch to gcc. It is a host-based solution designed to protect applications against buffer overflow attacks. Buffer overflow attack can inflict upon almost all arbitrary programs and is one of the most common vulnerabilities that can seriously compromise the security of a network-attached computer system. Using RAD compiler, users can prevent attackers from compromising their systems by changing the return address to execute injected code, which is the most common method used in buffer overflow attacks. Return Address Defender (RAD) automatically creates a safe area to store a copy of return addresses and automatically adds protection code into applications that it compiles to defend programs against buffer overflow attacks. Using it to protect a program does not need to modify the source code of the protected programs. The core router site components, PICA, generate and transfer path messages to delivery traffic volume and path information to a local traffic source detector. This mechanism allows an organization to back track DoS/DDoS attack sources. The most crucial part of Sky-walker is the edge router site component—CTCP. Many network security problems can be solved in a centralized TCP (CTCP) architecture, in which an organization's edge router transparently proxies every TCP connection between an internal host and an external host on the Internet. This dissertation describes the design, implementation, and evaluation of a CTCP router prototype that is built on the Linux kernel. By redirecting all packets targeting at non-existent or non-open-to-public ports to a CTCP socket which pretends to be the original receivers, CTCP could confirm the real identification of the packet sources, collect suspicious traffic from them, and make an illusion that the scanned target ports are all open, thus renders port scanning an useless effort. Under CTCP architecture, external hosts only interacts with a secure CTCP router; therefore, any OS fingerprinting attempt and DoS/DDoS attack targeting at TCP/IP implementation bugs could be thwarted. (Abstract shortened by UMI.)

Read the paper · More papers on PaperTik