An Approach to Detect Fileless Malware and Defend its Evasive mechanisms
B.N. Sanjay, D.C. Rakshith, R Akash, dr. Vinay V Hegde · 2018
Malware, or "malicious program," refers to any malicious program or code that is harmful to systems. Malware Analysis has always been an important topic of security threat research ever since the early days of computers. Over times, many different types of malwares have been evolved increasingly trying to be unnoticed by an antivirus software and attack the systems. Traditionally, malware attacks as we commonly know are files written to disk in one form or another that require execution in order to carry out their malicious activities. Fileless malware, on the other hand, is purposed to be memory resident only rather than writing artifacts to the filesystem, ideally leaving no trace after its execution, leveraging Operating System resident tools namely, Windows Management Instrumentation (WMI) or PowerShell propagate, execute its payload, or otherwise perform the tasks it is designed to perform. The purpose of all this for the attacker is to make post-infection forensics difficult. In addition, this form of attack makes it nearly impossible for antivirus signatures to trigger a detection. In this aspect, this paper will discuss the technical details of Fileless malware and their related attacks in depth. Finally, we will discuss on various Fileless malware detection and mitigation techniques in detail.