Polymorphic Penetration Testcode Carrier
Ming‐Hour Yang · International Journal of Digital Content Technology and its Applications · 2010
To diagnose the vulnerabilities of target system using a remote penetration test approach needs to avoid the modification of the security configuration of the target network. So the carrier of test codes needs to hide from the IDS filter out of our penetrating test codes. Hence, we proposed a polymorphic carrier which carries encrypted test codes and diversified decrypters, and, the proposed carrier is also able to adjust the OP code distribution to make it look like a normal packet. To make sure whether it can hide from the detection of an intrusion detection system and deliver the test codes to target system, we use simulation to analyze whether IDS such as STRIDE and APE can successfully detect the polymorphic test codes that we created, and whether the created carrier has a 90% or above possibility of successful execution in target system.