首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >FAROS: Illuminating In-memory Injection Attacks via Provenance-Based Whole-System Dynamic Information Flow Tracking
【24h】

FAROS: Illuminating In-memory Injection Attacks via Provenance-Based Whole-System Dynamic Information Flow Tracking

机译:FAROS:通过基于源的整个系统动态信息流跟踪来阐明内存中的注入攻击

获取原文

摘要

In-memory injection attacks are extremely challenging to reverse engineer because they operate stealthily without leaving artifacts in the system or in any easily observable events from outside of a virtual machine. Because these attacks perform their actions in memory only, current malware analysis solutions cannot expose their behavior. This paper introduces FAROS^1 a reverse engineering tool for Windows malware analysis based on dynamic information flow tracking (DIFT), which can flag stealthy in-memory-only malware injection attacks by leveraging the synergy of: (i) whole-system taint analysis; (ii) per security policy-based handling of the challenge of indirect flows via the application of tags of different types, and (iii) the use of tags with fine-grained provenance information. We evaluated FAROS with six advanced in-memory-injecting malware and it flagged the attacks for all samples. We also analyzed FAROS' false positive rate with 90 non-injecting malware samples and 14 benign software from various categories. FAROS presented a very low false positive rate of 2%, which shows its potential towards practical solutions against advanced in-memory-only anti-reverse-engineering attacks.
机译:内存中注入攻击对逆向工程人员来说是极具挑战性的,因为它们可以隐秘地运行,而不会在系统中或在虚拟机外部容易观察到的事件中留下工件。由于这些攻击仅在内存中执行其操作,因此当前的恶意软件分析解决方案无法揭示其行为。本文介绍了FAROS ^ 1,它是一种基于动态信息流跟踪(DIFT)的Windows恶意软件分析的逆向工程工具,可以利用以下协同作用来标记仅在内存中进行秘密的恶意软件注入攻击:(i)整个系统污染分析; (ii)通过应用不同类型的标签,基于安全策略对间接流的挑战进行处理,以及(iii)使用带有细粒度出处信息的标签。我们用六种高级内存注入恶意软件评估了FAROS,并标记了所有样本的攻击。我们还使用90种非注入恶意软件样本和14种来自各个类别的良性软件来分析FAROS的误报率。 FAROS的假阳性率非常低,仅为2%,这表明它有可能针对实际的解决方案,以解决仅针对内存中的高级逆向工程攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号