Endpoint Detection and Response for Fileless Malware and LOLBin Threats


연구 분야: Safety



학회: 2024 15th International Conference on Computing Communication and Networking Technologies (ICCCNT)


초록

The escalating threat posed by fileless attacks and Living-off-the-Land (LotL) techniques underscores the need for advanced detection mechanisms in cybersecurity. Fileless attacks circumvent traditional antivirus detection by operating within system memory, leveraging trusted tools and evading scrutiny. Concurrently, LotL attacks utilize system-integrated binaries to infiltrate and persist within systems, challenging detection methodologies. This study addresses these challenges by proposing a novel method for identifying Living off-the-land binaries and fileless malware patterns. Leveraging behavioral analysis in conjunction with YARA rules, the approach involves developing a script, for malicious instances and events in the system. Executing the script in controlled environments with malware simulations, the script demonstrated promising capabilities in detecting the malwares.


Author Profile
R Harish

Centre for Cybersecurity Systems and Networks Amrita Vishwa Vidyapeetham Amritapuri India

Andorra
Author Profile
M P Swapna

Centre for Cybersecurity Systems and Networks Amrita Vishwa Vidyapeetham Amritapuri India

Andorra

📄 논문 정보

발행 연도 2024년
인용수 2
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (513건)