当前位置:首页 > 报告详情

你的就是我的-自动化远程攻击复用与Shellcode移植.pdf

上传人: 云闲 编号:92526 2021-01-01 46页 1.40MB

1、卡内基梅隆大学你的就是我的:自动化远程攻击自动化远程攻击复用与复用与ShellcodeShellcode移植移植1这不是一个广告2流离:当你成为【杀】的目标时,你可以弃一张牌,将此【杀】转移给你攻击范围内的另一名角色。(该角色不得是【杀】的使用者)这不是一个广告Ricochet 攻击3将收到的攻击转移给他人。Ricochet 在 CTF 攻防竞赛中的应用4“Stealing and replaying exploits has become very popular;basically,it is the main way in which most teams attack others t

2、hese days.”-Shellphish“We inspected network traffic to find new vulnerabilities,which helped us score points and win DEFCON CTF.”-PPPRicochet 在现实生活中的应用A control flow hijacking exploit:Deviates the control flow of the vulnerable program,and Leads the program to carry out the malicious computation con

3、trolled by the attacker.5Ricochet 在现实生活中的应用A control flow hijacking exploit:Deviates the control flow of the vulnerable program,and Leads the program to carry out the malicious computationcontrolled by the attacker.6Shellcode7Steal a File ShellcodeExisting ExploitRicochet for Control Flow Hijacking

4、Exploits8Steal a File ShellcodeExisting ExploitInstall Malware ShellcodeReplacement ShellcodeRicochet for Control Flow Hijacking ExploitsShellcode Transplant9Steal a File ShellcodeExisting ExploitInstall Malware ShellcodeModified ExploitShellcode Transplant10Steal a File ShellcodeExisting ExploitIns

5、tall Malware ShellcodeReplacement ShellcodeModified ExploitShellcode Transplant11Existing ExploitSWhile Executing Shellcodef(S)SShellSwap:Automatic Shellcode Transplant112Fish WangYan ShoshitaishviliDavid BrumleyTiffany Bao1 T.Bao,Y.Shoshitaishvili,R.Wang and D.Brumley.Your Exploit is Mine:Automatic

6、 Shellcode Transplant for Remote Exploits,Proceedings of the 38th IEEE Symposium on Security and Privacy,2017.Previous Approach2132 D.K.Sean Heelan.Automatic Generation of Control Flow Hijacking Exploits for Software Vulnerabilities.141.Execute the program with symbolic inputs.2390a045Captured Explo

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了计算机安全领域中的自动化攻击技术。文中提到了卡内基梅隆大学的研究人员提出了一个名为ShellSwap的技术,该技术可以自动化地移植远程攻击中的Shellcode,提高了攻击的有效性。研究结果显示,使用ShellSwap技术,在100个案例中有85%的攻击成功,而在使用传统方法时,只有31%的攻击成功。此外,文中还提到,攻击者的攻击技术可以帮助他们在游戏中取得优势,但同时也可能受到受害者的反击。最后,文章指出,修补程序可以提高防御能力,但修补程序生成技术在游戏中可能并不实用,因为玩家可能不想修补。
"自动化远程攻击复用技术如何工作?" "Shellcode移植技术在现实生活中的应用有哪些?" "游戏理论模型如何影响网络安全攻防游戏?"
客服
商务合作
小程序
服务号
折叠