李承达
IBM
全球首席信息安全架构师
The IBM fundamental approach to threat
protection
•Stays ahead of the threat
with pre-emptive
protection that stops
things from breaking
the window
•Looks for methods that can
break
the window
•Keeping up can
be challenging
IBM protects the vulnerability Other products only block the exploits
IBM PROTECTION…
VULNERABILITY…
•Can be used to do
something unintended
•Can be exploited
in multiple ways
•Many different exploits can
target a single vulnerability
•Not all exploits
are publicly available,
and mutation is common
A weakness in a system A method used to gain system entry
versus EXPLOIT
versus OTHER PRODUCTS
7 or more years!
What is PAM?
§ The Protocol Analysis Module (PAM) is at the core of many IBM security products
- XGS next-generation intrusion prevention system (IPS)
§ PAM uses Deep Packet Inspection (DPI) to thoroughly inspect packets at wire speed
- processes up to 25 Gbps on the XGS 7100 appliance.
XGS
Inspects 500 protocols / file types
Reports 5964 signatures
Covers 30,000+ vulnerabilities
PAM
approved network traffic
network traffic
PAM does more with less
5,459 attack signatures* cover 30,000+ vulnerabilities as of March 2016
20,327 CVEs
additional 5,534 BIDs
additional 482 OSVDB
Leading industry analysts recently commented:
IBM's Protocol Analysis Module (PAM) is still leading the market in its ability to provide
low false positives and protection for entire classes of vulnerabilities, with the smallest
number of signatures on the market.
additional 4,425 SecChkIDs
Common Vulnerabilities and Exposures
Bugtraq ID
Open Source
Vulnerability
DB X-Force DB
Security
Check
* PAM also contains 497 audit signatures and 8 status signatures
PAM parses each frame, layer by layer
Ethernet
Header
IP Header TCP Header HTTP Header Application Data
(compressed HTML)
IP Header TCP Header HTTP Header Application Data
(compressed HTML)
TCP Header HTTP Header Application Data
(compressed HTML)
HTTP Header Application Data
(compressed HTML)
Application Data
(compressed HTML)
Data Link
(Layer 2)
Content
Layer
Network
Protocol
Transport
Protocol
Session
Protocol
PAM
6
IGMP
IPv4
XML
HTML
Image File
JavaScript
Email Body
PDF
Flash
Content
Layer
TCP
UDP
ICMP
FTP
TFTP
340 protocol parsers
(ISO layers 3-5)
161 content parsers
(ISO layers 6-7)
PAM Parser Overview
IPv6
4in6
6in4
IM
DNS
IMAP
POP3
SMTP
HTTP
Layer 3 Layer 4 Layer 5 Layers 6-7
TCP
UDP
TLS
syslog
PAM Protocol Heuristics (layer 5)
Approximately 120 protocol
parsers identified
heuristically
RADIUS
IMAP
POP3
SMTP
HTTP
TCP
Heuristic
-or-
Port
Association
UDP
Heuristic
-or-
Port
Association
“GET”… -or- port 80
ports 110, 995
“* OK ” rsp -or- port 143
“220…SMTP” rsp -or- port 25
“\x16\x03 …”
ports 1812,1813,1645,1646
“<…” -or- ports 514,515
new or “lifted”
connection
new packet
or “flow”
HTML
PDF
gzip
Layer 5
-or-
Embedded
Content
PAM Content Heuristics (layer 6-7)
Approximately 130 content
parsers identified
heuristically
Content
Heuristic
-or-
Mime Type
-or-
File
Extension
new
content
“<!DOCTYPE HTML”
“text/html”,…
.htm or .html
“%PDF”
“application/pdf”,…
.pdf
“\x1f\x8b\x08"”
“application/x-compressed”,…
.gz or .tgz
Internet
Printing
Protocol
"application/ipp"
Example of Deep Packet Inspection (1 of 5)
This is an HTTP 200 response transmitted in 99 TCP segments (packets) over IPv4
Example of Deep Packet Inspection (2 of 5)
The HTTP response uses Chunked Encoding dividing the payload into 46 chunks.
Example of Deep Packet Inspection (3 of 5)
The HTTP “chunked” payload is compressed in gzip format!
Example of Deep Packet Inspection (4 of 5)
The content of the gzip compressed payload is a PDF file.
Example of Deep Packet Inspection (5 of 5)
Hidden in the PDF file is a malicious .bmp image file, which PAM catches
2136000 (PDF_XFA_RLE_BMP_Overflow) on frame 266
intruder=:80
victim=:49825
protocolflags=TCP [ACK]
reporttype=SRC_ATTACKS_DST
adapterid=0
time="2013-09-25 22:25:"
resultflags=TCP
priority=High
URL=/
server=
accessed=yes
code=200
protocol=http
skip entry count=16777216
pdfObj=5
compressed=gzip
Parses
HTTP
response
in 99 TCP
packets
Accounts
for 46
chunks of
HTTP
payload
Decompress
es
gzip-
encoded
HTTP
payload
Parses the
PDF file
Parses
embedd
ed BMP
and
triggers
Ahead of The Threat (AOTT)
• AOTT – pre-existing coverage for a
vulnerability on the day it is publicly
reported/exploited
• AOTT – may refer to IPS Virtual Patch™
Policy – protects systems between
vulnerability/exploit disclosure and the
application of a patch
15
Criteria for AOTT examples in this
presentation:
1. At least 90 days of pre-existing PAM
coverage
2. Default Blocked if using
“Trust X-Force”
3. Notable vendors
(. Microsoft, Adobe, HP, Oracle,…)
4. Recent – 2012 to present
5. CVSS base score 5 or higher
X-Force Top 100 Recent AOTT Coverage
(blocking coverage at least 90 days ahead of the threat for notable vendors since 2012 with CVSS >= 5)
Microsoft (cont)
CVE-2014-6343 yrs
CVE-2014-6332 yrs
CVE-2014-2799 yrs
CVE-2014-2797 yrs
CVE-2014-1811 yrs
CVE-2014-1761 yrs
CVE-2013-3906 yrs
CVE-2013-3893 yrs
CVE-2013-3163 yrs
CVE-2013-1331 yrs
CVE-2013-1347 yrs
CVE-2013-1313 yrs
CVE-2013-0026 yrs
CVE-2013-0025 yrs
CVE-2012-4781 yrs
CVE-2012-2522 yrs
CVE-2012-1891 yrs
CVE-2012-1879 yrs
CVE-2012-1878 yrs
CVE-2012-1876 yrs
CVE-2012-1875 yrs
CVE-2012-0171 yrs
CVE-2012-0170 yrs
CVE-2012-0169 yrs
CVE-2012-0159 yrs
CVE-2012-0158 yrs
CVE-2012-0155 yrs
CVE-2012-0016 yrs
CVE-2012-0011 yrs
CVE-2012-0003 yrs
NGINX
CVE-2014-3556 yrs
CVE-2013-2070 yrs
Adobe
CVE-2015-5097 yrs
CVE-2014-8438 yrs
CVE-2013-3346 yrs
CVE-2013-2729 yrs
CVE-2013-2555 yrs
CVE-2013-0634 yrs
CVE-2012-4170 yrs
CVE-2012-1535 yrs
CVE-2012-0769 yrs
CVE-2012-0768 yrs
BID-52632 yrs
Apache
CVE-2013-2251 yrs
CVE-2013-2135 yrs
CVE-2013-2134 yrs
CVE-2013-2115 yrs
CVE-2013-1966 yrs
CVE-2012-0838 yrs
CVE-2012-0391 yrs
Apple
CVE-2012-3753 yrs
CA
BID-51915 yrs
GNU
CVE-2015-0235 yrs
ISC
CVE-2012-3571 yrs
CVE-2012-3523 yrs
Google
CVE-2015-3864 yrs
CVE-2015-3829 yrs
CVE-2015-3828 yrs
CVE-2015-3827 yrs
CVE-2015-3826 yrs
CVE-2015-3824 yrs
CVE-2015-1539 yrs
CVE-2015-1538 yrs
BID-52632 yrs
HP
CVE-2014-7883 yrs
CVE-2014-2625 yrs
CVE-2014-2621 yrs
CVE-2014-2620 yrs
CVE-2014-2617 yrs
CVE-2013-6195 yrs
CVE-2013-4799 yrs
CVE-2012-5201 yrs
Microsoft
CVE-2016-0062 yrs
CVE-2015-6143 yrs
CVE-2015-6142 yrs
CVE-2015-6150 yrs
CVE-2015-6087 yrs
CVE-2015-2464 yrs
CVE-2015-2461 yrs
CVE-2015-2397 yrs
CVE-2015-1662 yrs
CVE-2015-0090 yrs
CVE-2015-0086 yrs
CVE-2014-6369 yrs
Novell
CVE-2015-0779 yrs
CVE-2012-0271 yrs
NTP
CVE-2013-5211 yrs
Oracle
CVE-2013-2465 yrs
CVE-2013-2463 yrs
CVE-2013-2431 yrs
CVE-2013-0431 yrs
CVE-2013-0422 yrs
BID-56791 yrs
BID-56772 yrs
CVE-2012-3342 yrs
PHP
CVE-2015-4022 yrs
CVE-2014-4049 yrs
PowerDNS
CVE-2015-1868 yrs
Samba
CVE-2014-0239 yrs
Squid
CVE-2013-4115 yrs
Average AHOTT = yrs
Average CVSS base =
X-Force Top 100 Recent AOTT Coverage
(blocking coverage at least 90 days ahead of the threat for notable vendors since 2012 with CVSS >= 5)
Microsoft (cont)
CVE-2014-6343 yrs
CVE-2014-6332 yrs
CVE-2014-2799 yrs
CVE-2014-2797 yrs
CVE-2014-1811 yrs
CVE-2014-1761 yrs
CVE-2013-3906 yrs
CVE-2013-3893 yrs
CVE-2013-3163 yrs
CVE-2013-1331 yrs
CVE-2013-1347 yrs
CVE-2013-1313 yrs
CVE-2013-0026 yrs
CVE-2013-0025 yrs
CVE-2012-4781 yrs
CVE-2012-2522 yrs
CVE-2012-1891 yrs
CVE-2012-1879 yrs
CVE-2012-1878 yrs
CVE-2012-1876 yrs
CVE-2012-1875 yrs
CVE-2012-0171 yrs
CVE-2012-0170 yrs
CVE-2012-0169 yrs
CVE-2012-0159 yrs
CVE-2012-0158 yrs
CVE-2012-0155 yrs
CVE-2012-0016 yrs
CVE-2012-0011 yrs
CVE-2012-0003 yrs
NGINX
CVE-2014-3556 yrs
CVE-2013-2070 yrs
Adobe
CVE-2015-5097 yrs
CVE-2014-8438 yrs
CVE-2013-3346 yrs
CVE-2013-2729 yrs
CVE-2013-2555 yrs
CVE-2013-0634 yrs
CVE-2012-4170 yrs
CVE-2012-1535 yrs
CVE-2012-0769 yrs
CVE-2012-0768 yrs
BID-52632 yrs
Apache
CVE-2013-2251 yrs
CVE-2013-2135 yrs
CVE-2013-2134 yrs
CVE-2013-2115 yrs
CVE-2013-1966 yrs
CVE-2012-0838 yrs
CVE-2012-0391 yrs
Apple
CVE-2012-3753 yrs
CA
BID-51915 yrs
GNU
CVE-2015-0235 yrs
ISC
CVE-2012-3571 yrs
CVE-2012-3523 yrs
Google
CVE-2015-3864 yrs
CVE-2015-3829 yrs
CVE-2015-3828 yrs
CVE-2015-3827 yrs
CVE-2015-3826 yrs
CVE-2015-3824 yrs
CVE-2015-1539 yrs
CVE-2015-1538 yrs
BID-52632 yrs
HP
CVE-2014-7883 yrs
CVE-2014-2625 yrs
CVE-2014-2621 yrs
CVE-2014-2620 yrs
CVE-2014-2617 yrs
CVE-2013-6195 yrs
CVE-2013-4799 yrs
CVE-2012-5201 yrs
Microsoft
CVE-2016-0062 yrs
CVE-2015-6143 yrs
CVE-2015-6142 yrs
CVE-2015-6150 yrs
CVE-2015-6087 yrs
CVE-2015-2464 yrs
CVE-2015-2461 yrs
CVE-2015-2397 yrs
CVE-2015-1662 yrs
CVE-2015-0090 yrs
CVE-2015-0086 yrs
CVE-2014-6369 yrs
Novell
CVE-2015-0779 yrs
CVE-2012-0271 yrs
NTP
CVE-2013-5211 yrs
Oracle
CVE-2013-2465 yrs
CVE-2013-2463 yrs
CVE-2013-2431 yrs
CVE-2013-0431 yrs
CVE-2013-0422 yrs
BID-56791 yrs
BID-56772 yrs
CVE-2012-3342 yrs
PHP
CVE-2015-4022 yrs
CVE-2014-4049 yrs
PowerDNS
CVE-2015-1868 yrs
Samba
CVE-2014-0239 yrs
Squid
CVE-2013-4115 yrs
Let’s look at
4 examples
QuickTime
Protocol
anomaly
ZIP
History
repeats
JavaScript
Newest
AOTT
VBScript
X-Force
internal find
Average AHOTT = yrs
Average CVSS base =
2007: Protocol signature MOV_Container_Overflow (no CVE, no known exploits)
2009: Microsoft DirectX QuickTime code execution, CVE-2009-1539
00000000: moov <0> atomSize=0x0000018b, extent=0x0000018b
00000008: trak <1> atomSize=0x00000178, extent=0x00000180
00000010: tkhd <2> atomSize=0x0000005c, extent=0x0000006c
0000006c: mdia <2> atomSize=0x000000f0, extent=0x0000015c
00000074: mdhd <3> atomSize=0x00000020, extent=0x00000094
00000094: hdlr <3> atomSize=0x00000024, extent=0x000000b8
000000b8: minf <3> atomSize=0x000000a4, extent=0x0000015c
000000c0: stbl <4> atomSize=0x0000009c, extent=0x0000015c
000000c8: stsd <5> atomSize=0x00000020, extent=0x000000e8
000000d8: AAAA <6> atomSize=0x41414141, extent=0x41414219
000000e8: stts <5> atomSize=0x00000030, extent=0x00000118
2014: Adobe Flash Player and Adobe Air code execution, CVE-2014-8438
00007a7a: stsd <5> atomSize=0x00000096, extent=0x00007b10
00007a8a: avc1 <6> atomSize=0x00f00086, extent=0x00f07b10
2012: Real Networks RealPlayer .mp4 code execution, CVE-2012-1904
000001b7: stsd <5> atomSize=0x0000005b, extent=0x00000212
000001c7: mp4a <6> atomSize=0x6200004b, extent=0x62000212
atom overflows container
atom overflows container
atom overflows container
detects malformed QuickTime (.mov) files having an atom whose size exceeds its container size
AOTT coverage with MOV_Container_Overflow
released April 10, 2007
1: QuickTime
Protocol anomaly
Reported: Feb 9, 2016
AOTT coverage with Script_DOM_Unconditional_Undo
released June 9, 2015
detects a web script using .execCommand() followed unconditionally by .execCommand('Undo')
2015: Microsoft Internet Explorer code execution, CVE-2015-1753
Reported: June 9, 2015
(“…"); [details under NDA]
text….
("Undo");
2015: Microsoft Internet Explorer code execution, CVE-2015-6142
Microsoft Internet Explorer code execution, CVE-2015-6143
Reported: Dec 8, 2015
(“…"); [details under NDA]
document….
("Undo");
2016: Microsoft Internet Explorer code execution, CVE-2016-0062
….execCommand(“… [details under NDA]
…
("Undo", false, null);
2: JavaScript
newest AOTT
AOTT coverage with Zip_Directory_Traversal
released May 9, 2006
file=../../../../ROOT/
detects a ‘zip’ file having a filename containing "../" or "..\"
2006: IBM Lotus Notes compressed file preview directory traversal, CVE-2005-2619
Reported: February 10, 2006
A remote attacker could traverse directories and delete arbitrary files.
2010: Apache Tomcat WAR directory traversal, CVE-2009-2693
Reported: January 25, 2010
A remote attacker could create arbitrary files on the system outside of the Web root.
2013: Multiple HP products code execution, CVE-2012-5201
Reported: March 7, 2013
An attacker could execute arbitrary code on the system with SYSTEM privileges.
2015: ManageEngine ServiceDesk uploaded files code execution, SecChk 105842
Reported: August 20, 2015
An attacker could execute arbitrary code on the system.
3: ZIP
history repeats
CVE-2014-6332 Microsoft OLE automation array code execution
arbitrary code execution caused by improperly accessing an object in memory
May
2014
May 12: Vulnerability Discovered
X-Force researcher Robert Freeman finds the issue
May 16: Private Disclosure
Robert discloses to Microsoft and demonstrates RCE.
Microsoft determines “not in wild” and sets schedule
June 11: X-Force Blocking Coverage
Release of PAM signature
Script_Array_Overflow
detects VBScript code that overflows an array
Nov 11: Public Disclosure/Patch
Microsoft Super Tuesday includes CVE-2014-6332
June
July
Aug
Sep
Oct
Nov
4: VBScript
internal findAOTT coverage with Script_Array_Overflow
released June 11, 2015
Advantages of Pattern Matching versus Deep Packet
Inspection
Rules-based Pattern Matching
• Visibility of detection logic
• Customization and collaboration
• Faster time-to-market with new
coverage
Deep Packet Inspection (PAM)
• Ahead of the threat coverage
• Fewer false negatives (detects mutation)
• More coverage
• PAM covers 20,350 CVEs
• Snort references 6,350 CVEs (as of Feb 16, 2016)
• Protocol anomaly signatures
(MOV_Container_Overflow, TLS_Weak_Cipher_Suite, 6in4_Tunnel)
• Heuristics-based signatures
(SQL_Injection, Java_Malicious_Applet, Script_Suspicious_Score)
• Shellcode heuristics
(JavaScript_Shellcode_Detected, PDF_Shellcode_Detected)
• Flood detection and mitigation
(ActiveDirectory_Ldap_DoS, SMB_Mass_Login, VOIP_New_Call_Dos)
• Complex data leakage protection
(social security AND credit card in any order)
X-Force Top 100 Recent AOTT Coverage
(blocking coverage at least 90 days ahead of the threat for notable vendors since 2012 with CVSS >= 5)
Microsoft (cont)
CVE-2014-6343 yrs
CVE-2014-6332 yrs
CVE-2014-2799 yrs
CVE-2014-2797 yrs
CVE-2014-1811 yrs
CVE-2014-1761 yrs
CVE-2013-3906 yrs
CVE-2013-3893 yrs
CVE-2013-3163 yrs
CVE-2013-1331 yrs
CVE-2013-1347 yrs
CVE-2013-1313 yrs
CVE-2013-0026 yrs
CVE-2013-0025 yrs
CVE-2012-4781 yrs
CVE-2012-2522 yrs
CVE-2012-1891 yrs
CVE-2012-1879 yrs
CVE-2012-1878 yrs
CVE-2012-1876 yrs
CVE-2012-1875 yrs
CVE-2012-0171 yrs
CVE-2012-0170 yrs
CVE-2012-0169 yrs
CVE-2012-0159 yrs
CVE-2012-0158 yrs
CVE-2012-0155 yrs
CVE-2012-0016 yrs
CVE-2012-0011 yrs
CVE-2012-0003 yrs
NGINX
CVE-2014-3556 yrs
CVE-2013-2070 yrs
Adobe
CVE-2015-5097 yrs
CVE-2014-8438 yrs
CVE-2013-3346 yrs
CVE-2013-2729 yrs
CVE-2013-2555 yrs
CVE-2013-0634 yrs
CVE-2012-4170 yrs
CVE-2012-1535 yrs
CVE-2012-0769 yrs
CVE-2012-0768 yrs
BID-52632 yrs
Apache
CVE-2013-2251 yrs
CVE-2013-2135 yrs
CVE-2013-2134 yrs
CVE-2013-2115 yrs
CVE-2013-1966 yrs
CVE-2012-0838 yrs
CVE-2012-0391 yrs
Apple
CVE-2012-3753 yrs
CA
BID-51915 yrs
GNU
CVE-2015-0235 yrs
ISC
CVE-2012-3571 yrs
CVE-2012-3523 yrs
Google
CVE-2015-3864 yrs
CVE-2015-3829 yrs
CVE-2015-3828 yrs
CVE-2015-3827 yrs
CVE-2015-3826 yrs
CVE-2015-3824 yrs
CVE-2015-1539 yrs
CVE-2015-1538 yrs
BID-52632 yrs
HP
CVE-2014-7883 yrs
CVE-2014-2625 yrs
CVE-2014-2621 yrs
CVE-2014-2620 yrs
CVE-2014-2617 yrs
CVE-2013-6195 yrs
CVE-2013-4799 yrs
CVE-2012-5201 yrs
Microsoft
CVE-2016-0062 yrs
CVE-2015-6143 yrs
CVE-2015-6142 yrs
CVE-2015-6150 yrs
CVE-2015-6087 yrs
CVE-2015-2464 yrs
CVE-2015-2461 yrs
CVE-2015-2397 yrs
CVE-2015-1662 yrs
CVE-2015-0090 yrs
CVE-2015-0086 yrs
CVE-2014-6369 yrs
Novell
CVE-2015-0779 yrs
CVE-2012-0271 yrs
NTP
CVE-2013-5211 yrs
Oracle
CVE-2013-2465 yrs
CVE-2013-2463 yrs
CVE-2013-2431 yrs
CVE-2013-0431 yrs
CVE-2013-0422 yrs
BID-56791 yrs
BID-56772 yrs
CVE-2012-3342 yrs
PHP
CVE-2015-4022 yrs
CVE-2014-4049 yrs
PowerDNS
CVE-2015-1868 yrs
Samba
CVE-2014-0239 yrs
Squid
CVE-2013-4115 yrs
QuickTime
Protocol
anomaly
ZIP
History
repeats
JavaScript
Newest
AOTT
VBScript
X-Force
internal find
Average AHOTT = yrs
Average CVSS base =
Same
4 examples
overflow
Pattern Matching False Negative
2009: Microsoft DirectX QuickTime code execution, CVE-2009-1539
Known Exploit: 00000000: moov <0> atomSize=0x00000480, extent=0x0000048000000008: mvhd <1> atomSize=0x0000001c, extent=0x00000024
00000024: trak <1> atomSize=0x00000322, extent=0x00000346
0000002c: tkhd <2> atomSize=0x0000026c, extent=0x00000298
00000298: mdia <2> atomSize=0x0000011e, extent=0x000003b6
000002a0: mdhd <3> atomSize=0x000000ff, extent=0x0000039f
00000346: AAAA <1> atomSize=0x41414141, extent=0x41414487
00000480: XXXX <0> atomSize=0x58585858, extent=0x58585cd8
… flow:to_client,established; file_data; content:"AAAAAAAA|00 00 00|0stts|04 00 00
00|"; …
2009 PoC: 00000000: moov <0> atomSize=0x0000018b, extent=0x0000018b00000008: trak <1> atomSize=0x00000178, extent=0x00000180
00000010: tkhd <2> atomSize=0x0000005c, extent=0x0000006c
0000006c: mdia <2> atomSize=0x000000f0, extent=0x0000015c
00000074: mdhd <3> atomSize=0x00000020, extent=0x00000094
00000094: hdlr <3> atomSize=0x00000024, extent=0x000000b8
000000b8: minf <3> atomSize=0x000000a4, extent=0x0000015c
000000c0: stbl <4> atomSize=0x0000009c, extent=0x0000015c
000000c8: stsd <5> atomSize=0x00000020, extent=0x000000e8
000000d8: AAAA <6> atomSize=0x41414141, extent=0x41414219
000000e8: stts <5> atomSize=0x00000030, extent=0x00000118
PAM signature (2007):
MOV_Container_Overflow
Snort coverage:
overflow
if ((state->depth > 0) && (extent > state->atomExtent[state->depth-1]))
1: QuickTime
Protocol anomaly
Pattern Matching - rule per attack
2015-2016: Related Microsoft IE code execution vulnerabilities
CVE-2015-1753 Reported: June 9, 2015
CVE-2015-6142 Reported: Dec 8, 2015
… flow:to_server,established; file_data; … content:".execCommand"; within:100; nocase; …
nocase; content:".scrollIntoView"; within:100; nocase; content:".execCommand"; nocase;
content:"Undo"; within:25; nocase; …
… flow:to_server,established; file_data; content:"ms-beginUndoUnit"; fast_pattern:only;
content:"execCommand"; nocase; content:"undo"; within:10; nocase; …
CVE-2015-6143 Reported: Dec 8, 2015
… flow:to_server,established; file_data; content:".addEventListener"; nocase;
content:"DOMAttrModified"; within:25; nocase; content:".execCommand"; nocase; … nocase;
content:".execCommand"; nocase; content:"undo"; within:15; nocase; …
if (state->saw_execCommand && execCommandVulnerable && isUndo)
Snort coverage:
PAM signature (2015):
Script_DOM_Unconditional_Undo
2: JavaScript
newest AOTT
2006: IBM Lotus Notes compressed file preview directory traversal, CVE-2005-2619
2013: Multiple HP products code execution, CVE-2012-5201
--- no Snort coverage ---
… flow:to_server,established; content:"/imc/webdm/mibbrowser/mibFileUpload";
fast_pattern:only; http_uri; content:"..|5C|..|5C|..|5C|..|5C|"; http_client_body; …
… flow:to_server,established; content:"/imc/webdm/mibbrowser/mibFileUpload";
fast_pattern:only; http_uri; content:"../../../../"; http_client_body; …
2010: Apache Tomcat WAR directory traversal, CVE-2009-2693
--- no Snort coverage ---
Pattern Matching Lack of Coverage
2006-2015: Related Zip Traversal vulnerabilities
if (dirClimb(psom, &dirClimbState, zip->, zip->)) PAM signature (2006):
Zip_Directory_Traversal
Snort coverage:
3: ZIP
history repeats
2015: ManageEngine ServiceDesk code execution, SecChk 105842 (no CVE)
--- no Snort coverage ---
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data; content:"redim";
nocase; content:"preserve"; within:20; nocase; content:"(&h"; within:20; byte_test:6,>,1000,0,relative,string,hex; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service smtp;
reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:32473; rev:4;)
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data; content:"redim";
nocase; content:"preserve"; within:20; nocase; content:"("; within:20; byte_test:6,>,1000,0,relative,string,dec; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service smtp;
reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:32472; rev:4;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"redim"; nocase; content:"preserve"; within:20; nocase; content:"(&h"; within:20; byte_test:6,>,1000,0,relative,string,hex; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service
ftp-data, service http, service imap, service pop3; reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:32471; rev:4;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"redim"; nocase; content:"preserve"; within:20; nocase; content:"("; within:20; byte_test:6,>,1000,0,relative,string,dec; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service
ftp-data, service http, service imap, service pop3; reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:32470; rev:4;)
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data;
content:"myarray"; content:"chrw"; within:10; content:"chrw"; within:20; content:"32767"; within:10; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service smtp; reference:cve,2014-6332;
reference:url, classtype:attempted-dos; sid:32565; rev:4;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"myarray"; content:"chrw"; within:10; content:"chrw"; within:20; content:"32767"; within:10; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service ftp-data, service http,
service imap, service pop3; reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:32564; rev:4;)
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data; content:"redim
Preserve arr(&h8000002)"; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; reference:cve,2014-6332; reference:url,
classtype:attempted-dos; sid:32630; rev:2;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"redim Preserve arr(&h8000002)"; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service ftp-data, service http, service imap, service pop3; reference:cve,2014-6332;
reference:url, classtype:attempted-dos; sid:32629; rev:2;)
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data;
content:"HIvIauuKF6i9p*qI1wE8J*znjk3Yl8td"; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; reference:cve,2014-6332; reference:url,
064; classtype:attempted-dos; sid:33116; rev:2;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"HIvIauuKF6i9p*qI1wE8J*znjk3Yl8td"; fast_pattern:only; metadata:policy balanced-ips drop, policy security-ips drop, service ftp-data, service http, service imap, service pop3; reference:cve,2014-6332;
reference:url, classtype:attempted-dos; sid:33115; rev:2;)
./rules/:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_server,established; file_data; content:"76723";
content:"wrhc"; within:10; content:"wrhc"; within:20; content:"yarraym"; within:10; metadata:policy balanced-ips drop, policy security-ips drop, service smtp; reference:cve,2014-6332; reference:url,
us/security/bulletin/ms14-064; classtype:attempted-dos; sid:33980; rev:1;)
./rules/:alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; file_data;
content:"76723"; content:"wrhc"; within:10; content:"wrhc"; within:20; content:"yarraym"; within:10; metadata:policy balanced-ips drop, policy security-ips drop, service ftp-data, service http, service imap, service pop3;
reference:cve,2014-6332; reference:url, classtype:attempted-dos; sid:33979; rev:1;)
./rules/:# alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt"; flow:to_client,established; content:"new ActiveXObject";
content:""; within:30; content:"Run("; within:30; metadata:policy max-detect-ips drop, policy security-ips drop, service http; reference:cve,2014-6332; reference:url,
us/security/bulletin/ms14-064; classtype:attempted-user; sid:36896; rev:1;)
./rules/:# alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"EXPLOIT-KIT Known exploit kit obfuscation routine detected"; flow:to_client,established; content:"vbscript>"; content:"=Split("; within:40;
content:"UBound("; within:40; content:"+Chrw(eval("; within:40; content:"End Function"; within:40; metadata:policy max-detect-ips drop, policy security-ips drop, service http; reference:cve,2014-6332; classtype:attempted-user;
sid:36824; rev:1;)
Pattern Matching Large Rule Set
Microsoft OLE automation array code execution, CVE-2014-6332
int32 newArraySize = jcalc(args, len, NULL, NULL);
if ((newArraySize > threshold)
|| (state->builtChrwString && (state->suspiciousTraits & STmask(ST_Shell_Exec))))
PAM signature (2014):
Script_Array_Overflow
Snort coverage (14 rules):
4: VBScript
internal find
PAM supports OpenSignature
on XGSMany IBM customers use OpenSignature rules in addition to PAM, allowing custom
security rules and early response to a crisis. OpenSignature is 98% Snort compatible.
OpenSignature in PAM
• Most of the 340 supported protocol parsers
(the layer 5 protocols) are supported in
metadata:service, . HTTP, FTP, SIP,
MySQL, DNS, RADIUS, TLS, TNS.
For example, “metadata:service:rdp”
• Supports 160 content (file) types, with almost
all supported in metadata:service.
For example, “metadata:service:pdf”
“metadata:service” in OpenSignature
OpenSignature provides additional “service points” because it is implemented within
PAM.
Snort
• By default, supports 25 preprocessor
protocols (. http, ftp, smtp, dns) in the
Attribute Table, which are availabe for use
in metadata:service
• By default, supports no content (file) types
for targeted inspection. If needed,
administrators would have to create their
own file parsers using regular expressions
IBM X-Force monitors and analyzes the changing
threat landscape
Coverage
20,000+ devices
under contract
15B+ events
managed per day
133 monitored
countries (MSS)
1,000+ security
related patents
100M+ customers protected
from
fraudulent transactions
Depth
25B analyzed
web pages & images
8M spam &
phishing attacks daily
89K documented
vulnerabilities
860K malicious IP
addresses
Millions of unique malware
samples
谢 谢