首页> 外文期刊>Indian Journal of Science and Technology >Analysis of Exploit Delivery Technique using Steganography
【24h】

Analysis of Exploit Delivery Technique using Steganography

机译:利用隐写术分析漏洞利用技术

获取原文
           

摘要

Background/Objectives: Steganography is a technique that hides the secret information in an image and makes it imperceptible. The purpose of steganography is not only to keep others from knowing the hidden information but also to keep others from thinking that the information even exists. Hence the attacker takes this opportunity to hide the exploit code in the image and perform the desired attacks on a system. This is based on a tool named Stegosploit. It also explores the aberrance of images when these images are encoded with JavaScript code and analyzes the impact of this technique. It also provides the proposition of mitigation method for this attack. Methods/Statistical Analysis: In this attack, a malicious code is encoded in the image and when an image is downloaded, the malicious code is executed which performs the intended attack. Since the consequences of the attack depend on the malicious code, there is no predefined signature or behaviour of the attack. Therefore, it is difficult to identify this attack. This paper makes use of steganography as a tool for hiding the JavaScript code which exploits a system by deleting a file, starting a key logger in the background, stealing the sensitive information, damaging the resources of the system etc. Findings: It is observed that a potentially harmful code can be easily hidden in an image but few restrictions can be observed. Sometimes the encoding process is not proper which can lead to loss of code. Moreover, the difference in weighted average of pixels can act as a good mechanism to detect the presence of such an attack at end user system. Applications/Improvement: It helps the users especially students about the new technology that can endangered the privacy as well as their important data. Moreover, it depicts how modern day technology can be used by terrorists for secretly broadcasting messages. This raises a flag for security agencies to stay ahead in the game.
机译:背景/目的:隐秘术是一种将秘​​密信息隐藏在图像中并使其难以察觉的技术。隐写术的目的不仅是让其他人不了解隐藏的信息,而且还使其他人不认为该信息甚至存在。因此,攻击者借此机会将漏洞利用代码隐藏在映像中,并在系统上执行所需的攻击。这基于一个名为Stegosploit的工具。它还探索了使用JavaScript代码对这些图像进行编码时的图像异常,并分析了此技术的影响。它还为这种攻击提供了缓解方法的命题。方法/统计分析:在这种攻击中,恶意代码被编码在映像中,当下载映像时,将执行恶意代码,从而执行预期的攻击。由于攻击的后果取决于恶意代码,因此没有预定义的签名或攻击行为。因此,很难识别这种攻击。本文利用隐写术作为隐藏JavaScript代码的工具,该JavaScript代码通过删除文件,在后台启动密钥记录器,窃取敏感信息,破坏系统资源等来利用系统代码。研究发现:潜在的有害代码很容易隐藏在图像中,但几乎没有限制。有时,编码过程不合适,这可能会导致代码丢失。此外,像素加权平均的差异可以用作检测最终用户系统中此类攻击的存在的良好机制。应用程序/改进:它可以帮助用户(尤其是学生)了解可能危及隐私及其重要数据的新技术。此外,它还描绘了恐怖分子如何利用现代技术秘密广播消息。这为安全机构在游戏中保持领先地位升起了旗帜。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号