A Rule Generation Method With High Understandability Against Obfuscated Attack Patterns in Log4Shell for IPS and IDS Based on Given Obfuscation Techniques
Yudai Yamamoto, Shingo Yamaguchi · 2023
We propose a rule generation method for Log4Shell obfuscated attack patterns for IPS and IDS by pattern matching with prior knowledge consisting of obfuscation techniques given in the form of regexes. In this method, regex patterns are transformed into finite automaton and matched with given URL strings. Pattern matching produces a fitness table of patterns that contains the number of times each prior knowledge and match was made. By using this, the proposed method can handle the case where a single obfuscation technique is used as well as the case where multiple obfuscation techniques are combined, and the multiple patterns are logically concatenated into a single regex. By applying this to a template, rules that can be applied to IPS and IDS are generated. Then, from the generated regexes, an automaton-based visualization is performed, which can reveal the relationship between the generated regexes and the regexes given as prior knowledge and obfuscation techniques for a given URL string. Experimental results show that the method can reduce the complexity of regexes by 40% compared to the conventional method in which rules are created by humans.