首页> 外文会议>International Symposium on Cyber Security Cryptography and Machine Learning >Detection in the Dark - Exploiting XSS Vulnerability in CC Panels to Detect Malwares
【24h】

Detection in the Dark - Exploiting XSS Vulnerability in CC Panels to Detect Malwares

机译:在C&C面板中的暗漏XSS漏洞中的检测检测恶意

获取原文

摘要

Numerous defense techniques exist for preventing and detecting malware on end stations and servers (endpoints). Although these techniques are widely deployed on enterprise networks, many types of malware manage to stay under the radar, executing their malicious actions time and again. Therefore, a more creative and effective solution is necessary, especially as classic threat detection techniques do not utilize all stages of the attack kill chain in their attempt to detect malicious behavior on endpoints. In this paper, we propose a novel approach for detecting malware. Our approach uses offensive and defensive techniques for detecting active malware attacks by exploiting the vulnerabilities of their command and control panels and manipulating significant values in the operating systems of endpoints - in order to attack these panels and utilize trusted communications between them and the infected machine.
机译:存在许多防范技术用于防止和检测端站和服务器(端点)上的恶意软件。虽然这些技术广泛部署在企业网络上,但许多类型的恶意软件可以留在雷达下,执行他们的恶意行为时间。因此,需要更具创造性和有效的解决方案,特别是由于经典威胁检测技术不利用攻击杀戮链的所有阶段试图在端点上检测恶意行为。在本文中,我们提出了一种用于检测恶意软件的新方法。我们的方法使用令人反感和防御性技术来通过利用其命令和控制面板的漏洞并在端点的操作系统中操纵显着的值来检测活动恶意软件攻击 - 以便攻击这些面板并利用它们之间的可信通信和受感染的机器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号