This paper investigates the exploitation of Windows binary files, with a specific focus on examples like the Egregor Ransomware, which leverages Bitsadmin and Rundll32 binaries. The study examines the tactics, techniques, and procedures (TTPs) of LOLBins exploitation through the lens of the MITRE ATT&CK framework. Due to the legitimate nature of LOLBins, their misuse often evades detection by antivirus software and endpoint detection and response (EDR) systems, which primarily rely on signature and rule-based methodologies. By pioneering the integration of NLP and SVM, this study aims to enhance the detection capabilities for LOLBins exploitation, offering a more robust and innovative solution than traditional signature and rule-based detection methods. The study also provides a comprehensive framework for evaluating the threat level of executed commands, enhancing the practical application of the research findings.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Modeling and Optimizing Detection of Operating System Binaries Exploitation Using Support Vector Machine

  • Nor Azlina Abd Rahman,
  • Jalil Md Desa,
  • Ali Ashkan Jalooli

摘要

This paper investigates the exploitation of Windows binary files, with a specific focus on examples like the Egregor Ransomware, which leverages Bitsadmin and Rundll32 binaries. The study examines the tactics, techniques, and procedures (TTPs) of LOLBins exploitation through the lens of the MITRE ATT&CK framework. Due to the legitimate nature of LOLBins, their misuse often evades detection by antivirus software and endpoint detection and response (EDR) systems, which primarily rely on signature and rule-based methodologies. By pioneering the integration of NLP and SVM, this study aims to enhance the detection capabilities for LOLBins exploitation, offering a more robust and innovative solution than traditional signature and rule-based detection methods. The study also provides a comprehensive framework for evaluating the threat level of executed commands, enhancing the practical application of the research findings.