Preventing File-Less Attacks with Machine Learning Techniques

Alexandru Gabriel Bucevschi, Gheorghe Balan, Dumitru Bogdan Prelipcean · 2019

The cyber-threat detection problem is a complex one due to the large diversity of attacks, increasing number of prevalent samples and to the arms race between attackers and security researchers. A new class of attacks which appeared in the past years is modifying its spreading and action methods in order to become non-persistent. Being non-persistent, the usual detection and analysis methods which are file oriented, do not work anymore. Therefore, several solutions became available like memory introspection, process activity monitoring or application enforcement. However, these solutions are time consuming, therefore their usage impose some additional resources needs. In this paper we discuss an entry-level anomaly detection method of the command lines arguments which are passed to the most known system tools generally available in Windows and not only. Some of these tools are used for years in companies to automatize tasks, but only in the recent period they became a powerful tool for the attackers. The method is based on a derived version of Perceptron and consists in feature extraction and building a machine learning model.

Read the paper · More papers on PaperTik