Dazzle-attack: Anti-Forensic Server-side Attack via Fail-Free Dynamic State Machine


연구 분야: Strategies



학회: International Conference on Information Security Applications


초록

Server-side malware is one of the prevalent threats that can affect a large number of clients who visit the compromised server. In this paper, we propose DAZZLE-ATTACK, a new advanced server-side attack that is resilient to forensic analysis such as reverse-engineering. DAZZLE-ATTACK retrieves typical (and non-suspicious) contents from benign and uncompromised websites to avoid detection and mislead the investigation to erroneously associate the attacks with benign websites. DAZZLE-ATTACK leverages a specialized state-machine that accepts any inputs and produces outputs with respect to the inputs, which substantially enlarges the input-output space and makes reverse-engineering effort significantly difficult. We develop a prototype of DAZZLE-ATTACK and conduct empirical evaluation of DAZZLE-ATTACK to show that it imposes significant challenges to forensic analysis.


Author Profile
Bora Lee

University of Virginia Charlottesville VA USA

United States
Author Profile
Kyungchan Lim

The University of Tennessee Tennessee USA

United States
Author Profile
JiHo Lee

University of Virginia Charlottesville VA USA

United States

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Georgia, United States, Korea
사이트 Springer
좋아요 수 0

연관 논문 목록 (174건)