首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >CHARACTERISTICS OF MALICIOUS DLLS IN WINDOWS MEMORY
【24h】

CHARACTERISTICS OF MALICIOUS DLLS IN WINDOWS MEMORY

机译:Windows内存中恶意DLL的特征

获取原文

摘要

Dynamic link library (DLL) injection is a method of forcing a running process to load a DLL into its address space. Malware authors use DLL injection to hide their code while it executes on a system. Due to the large number and variety of DLLs in modern Windows systems, distinguishing a malicious DLL from a legitimate DLL in an arbitrary process is non-trivial and often requires the use of previously-established indicators of compromise. Additionally, the DLLs loaded in a process naturally fluctuate over time, adding to the difficulty of identifying malicious DLLs. Machine learning has been shown to be a viable approach for classifying malicious software, but it has not as yet been applied to malware in memory images. In order to identify the behavior of malicious DLLs that were injected into processes, 33,160 Windows 7 x86 memory images were generated from a set of malware samples obtained from VirusShare. DLL artifacts were extracted from the memory images and analyzed to identify behavioral patterns of malicious and legitimate DLLs. These patterns highlight features of DLLs that can be applied as heuristics to help identify malicious injected DLLs in Windows 7 memory. They also establish that machine learning is a viable approach for classifying injected DLLs in Windows memory.
机译:动态链接库(DLL)注射是一种强制运行过程将DLL加载到其地址空间中的方法。恶意软件作者使用DLL注入在系统上执行时隐藏其代码。由于现代Windows系统中的数量和各种DLL,在任意过程中与合法DLL区分恶意DLL是非微不足道的,并且通常需要使用先前建立的妥协指标。此外,加载过程中加载的DLL自然会随着时间的推移而自然地波动,增加了识别恶意DLL的难度。已经显示机器学习是一种用于对恶意软件进行分类的可行方法,但它尚未应用于内存图像中的恶意软件。为了识别注入进程的恶意DLL的行为,从从VirusShare获得的一组恶意软件样本生成33,160Windows 7 X86存储器映像。从存储器图像中提取DLL伪像,并分析以识别恶意和合法DLL的行为模式。这些模式突出显示可以应用为启发式的DLL的功能,以帮助识别Windows 7内存中的恶意注入的DLL。他们还建立了机器学习是一种可行的方法,可以在Windows内存中对注入的DLL进行分类。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号