A Packet Content-Oriented Remote Code Execution Attack Payload Detection Model
Enbo Sun,
Jiaxuan Han (),
Yiquan Li and
Cheng Huang
Additional contact information
Enbo Sun: The 30th Research Institute of China Electronics Technology Group Corporation, Chengdu 610041, China
Jiaxuan Han: School of Cyber Science and Engineering, Sichuan University, Chengdu 610207, China
Yiquan Li: The 30th Research Institute of China Electronics Technology Group Corporation, Chengdu 610041, China
Cheng Huang: School of Cyber Science and Engineering, Sichuan University, Chengdu 610207, China
Future Internet, 2024, vol. 16, issue 7, 1-18
Abstract:
In recent years, various Remote Code Execution vulnerabilities on the Internet have been exposed frequently; thus, more and more security researchers have begun to pay attention to the detection of Remote Code Execution attacks. In this paper, we focus on three kinds of common Remote Code Execution attacks: XML External Entity, Expression Language Injection, and Insecure Deserialization. We propose a packet content-oriented Remote Code Execution attack payload detection model. For the XML External Entity attack, we propose an algorithm to construct the use-definition chain of XML entities, and implement detection based on the integrity of the chain and the behavior of the chain’s tail node. For the Expression Language Injection and Insecure Deserialization attack, we extract 34 features to represent the string operation and the use of sensitive classes/methods in the code, and then train a machine learning model to implement detection. At the same time, we build a dataset to evaluate the effect of the proposed model. The evaluation results show that the model performs well in detecting XML External Entity attacks, achieving a precision of 0.85 and a recall of 0.94. Similarly, the model performs well in detecting Expression Language Injection and Insecure Deserialization attacks, achieving a precision of 0.99 and a recall of 0.88.
Keywords: remote code execution; XML external entity; expression language injection; insecure deserialization; network attack detection (search for similar items in EconPapers)
JEL-codes: O3 (search for similar items in EconPapers)
Date: 2024
References: View references in EconPapers View complete reference list from CitEc
Citations:
Downloads: (external link)
https://www.mdpi.com/1999-5903/16/7/235/pdf (application/pdf)
https://www.mdpi.com/1999-5903/16/7/235/ (text/html)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:gam:jftint:v:16:y:2024:i:7:p:235-:d:1427271
Access Statistics for this article
Future Internet is currently edited by Ms. Grace You
More articles in Future Internet from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().