The automatic patch-based exploit generation » Computer internet security  
Computer and internet security news
computer and networking security portal
 
|
|
|
News
|
Advertise
|
|
Products
|
Contact

The automatic patch-based exploit generation



Sunday, April 27, 2008, 0:34
This news item was posted in System Patching category and has 0 Comments so far.

The automatic patch-based exploit generation problem is: given a program P and a patched version of the program P’, automatically generate an exploit for the potentially unknown vulnerability present in P but fixed in P’. The techniques for automatic patch-based exploit generation, and show that some techniques can automatically generate exploits for vulnerable programs based upon patches provided via Windows Update.In many cases one is able to automatically generate exploits within minutes or less. Although our techniques may not work in all cases, a fundamental tenet of security is to conservatively estimate the capabilities of attackers. Thus, our results indicate that automatic patch-based exploit generation should be considered practical. One important security implication of our results is that current patch distribution schemes which stagger patch distribution over long time periods, such as Windows Update, may allow attackers who receive the patch first to compromise the significant fraction of vulnerable hosts who have not yet received the patch. Thus, it is  concluded  update schemes, such as Windows Update as currently implemented, can detract from overall security, and should be redesigned.

Attackers can simply wait for a patch to be released, use these techniques, and with reasonable chance, produce a working exploit within seconds. Coupled with a worm, all vulnerable hosts could be compromised before most are even aware a patch is available, let alone download it. Thus, Microsoft should redesign Windows Update. We propose solutions which prevent several possible schemes, some of which could be done with existing technology.

Related posts:

  1. IE7 to be Pushed via Automatic Updates
  2. What is zero day attack or exploit
  3. Microsoft has released an out-of-band patch
  4. One more Windows exploit found!
  5. Patch Compliance Assurance Mechanism
  6. WEP is an encryption scheme based on the RC-4 cipher

Related posts brought to you by Yet Another Related Posts Plugin.






You can leave a response, or trackback from your own site.

Leave a Reply





:::: Recent entries


 
Join My Community at MyBloglog!



My BlogCatalog BlogRank

Computers Blogs - Blog Top Sites