首页> 外文会议>International conference on cyber security cryptography and machine learning >Detection in the Dark - Exploiting XSS Vulnerability in CC Panels to Detect Malwares
【24h】

Detection in the Dark - Exploiting XSS Vulnerability in CC Panels to Detect Malwares

机译:在黑暗中检测-利用C&C面板中的XSS漏洞检测恶意软件

获取原文

摘要

Numerous defense techniques exist for preventing and detecting malware on end stations and servers (endpoints). Although these techniques are widely deployed on enterprise networks, many types of malware manage to stay under the radar, executing their malicious actions time and again. Therefore, a more creative and effective solution is necessary, especially as classic threat detection techniques do not utilize all stages of the attack kill chain in their attempt to detect malicious behavior on endpoints. In this paper, we propose a novel approach for detecting malware. Our approach uses offensive and defensive techniques for detecting active malware attacks by exploiting the vulnerabilities of their command and control panels and manipulating significant values in the operating systems of endpoints - in order to attack these panels and utilize trusted communications between them and the infected machine.
机译:存在许多用于预防和检测终端站和服务器(端点)上的恶意软件的防御技术。尽管这些技术已广泛部署在企业网络上,但许多类型的恶意软件设法躲在雷达下,一次又一次地执行其恶意行为。因此,有必要提供一种更具创造性和有效的解决方案,尤其是在经典威胁检测技术没有利用攻击杀伤链的所有阶段来尝试检测端点上的恶意行为时。在本文中,我们提出了一种检测恶意软件的新颖方法。我们的方法使用攻击性和防御性技术来检测活动的恶意软件攻击,方法是利用其命令和控制面板的漏洞并控制端点操作系统中的重要值-以便攻击这些面板并利用它们与受感染机器之间的可信通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号