A study of selected security measures against non-legitimate use of code

Peng Liu, George Kesidis, Yoon‐Chan Jhi · 2010

As many aspects of social and economic activities rapidly move to networks, computer security has never been more important. Many serious security issues have their origin in non-legitimate use of code. For example, code exploiting a vulnerability can be used in computer worms and viruses; code used without acquiring proper permission could conduct intellectual property theft; or code inserted with a malicious intention may be abused as spyware, botnet, or backdoors to cause many additional security problems. In this study, we consider two types of security issues that can be caused by a non-legitimate use of program code. First, we investigate self-propagating code, computer worms. To defend against worm spread, we propose PWC, a proactive worm containment solution for enterprises. PWC can stop - instead of just slow down - an infected host from releasing worm scans after merely 4 scans. Motivated by the observation that a worm uses a sustained outgoing packet rate, PWC gains infection awareness seconds before a signature or filter can be generated. To overcome denial-of-service possibly caused by such characteristic indicators of infection, PWC develops two new white-host detection (uninfected host detection) techniques: (a) the vulnerability time window lemma, and (b) the relaxation analysis. PWC does not rely on content-based signatures and thus it can quickly contain polymorphic worms. PWC is also resilient to containment evasion. PWC is not sensitive to worm scan rate, and is not protocol specific. Due to white-host detection, PWC causes minimal denial-of-service. Evaluation based on real traces and worm simulations demonstrates that PWC significantly outperforms Virus Throttle [1] in terms of number of released worm scans, number of hosts infected by local scans, and denial-of-service effects. Second, we study detection of illegally reused code. Reusing code can be done with malicious motives. Code theft is accomplished by cracking, reverse engineering, breaking into an enterprise network, spying, bribing, etc. In a sense, absence of effective methods to detect fraudulent use of program code has a negative influence to security. For a practical and effective method to detect software plagiarism, we propose value based plagiarism detection system (VaPD). Based on an observation that some critical runtime values are hard to be replaced or eliminated by semantics-preserving transformation techniques, we introduce a novel approach to dynamic characterization of executable programs. Leveraging such invariant values, our technique is resilient to various control and data obfuscation techniques. We show how the values can be extracted and refined to expose the critical values and how we can apply this runtime property to help solve problems in software plagiarism detection. We have implemented a prototype with a dynamic taint analyzer atop a generic processor emulator, QEMU 0.9.1. Our experimental results show that our value-based plagiarism detection method successfully discriminates 34 plagiarisms obfuscated by SandMark, plagiarisms heavily obfuscated by Klass-Master, C programs obfuscated by Thicket, and executable files obfuscated by Loco/Diablo. In summary, this study presents two security measures against non-legitimate use of program code. First, a worm containment technique is proposed to stop the spread of self-propagating malicious code within enterprise networks. Second, a software plagiarism detection technique is proposed as a practical measure to deter theft accompanied by software plagiarism activity. These two techniques contribute to uninterrupted communications as well as promote a more healthy and trustworthy environment for the software industry.

Read the paper · More papers on PaperTik