首页> 外文会议>International conference on ICT systems security and privacy protection >IMShell-Dec: Pay More Attention to External Links in PowerShell
【24h】

IMShell-Dec: Pay More Attention to External Links in PowerShell

机译:Imshell-Dec:更多地关注PowerShell的外部链接

获取原文

摘要

Windows proposes the PowerShell shell command line to substitute the traditional CMD. However, it is often utilized by the attacker to invade the victim because of its versatile functionality. In this paper, we investigate an attack combined PowerShell and image steganography. Compared with the traditional method, this attack can deceive the defender by hiding its malicious contents in benign images. To effectively detect this attack, we propose a framework IMShell-Dec, whose main target is to check external links before the execution of PowerShell script. IMShell-Dec trains a machine learning classifier with image examples, where the features are generated by merging histograms of three image color channels. Then IMShell-Dec examines the script through tracking and classifying the related images. The detector achieves more than 95% precision in 9,589 high-definition images.
机译:Windows提出了PowerShell Shell命令行以替换传统的CMD。但是,由于其多功能功能,攻击者通常由攻击者侵入受害者。在本文中,我们调查了攻击组合的PowerShell和图像隐写术。与传统方法相比,这种攻击可以通过在良性图像中隐藏其恶意内容来欺骗防御者。为了有效地检测到这次攻击,我们提出了一个框架IMShell-Dec,其主要目标是在执行PowerShell脚本之前检查外部链接。 IMShell-Dec列举机器学习分类器,其中具有图像示例,其中通过合并三个图像颜色通道的直方图来生成特征。然后imshell-dec通过跟踪和分类相关图像来检查脚本。探测器在9,589个高清图像中达到95%以上的精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号