Next-Generation Antivirus endowed with Web-Server SandBox Applied to Audit Fileless Attack

Sidney Marlon Lopes de Lima, Sthéfano Silva, Ricardo Paranhos Pinheiro, Danilo Souza, Petrônio G. Lopes, Rafael Lima, Jemerson R. de Oliveira, Thyago de Amorim Monteiro, Sergio Murilo Maciel Fernandes, Edison de Queiroz Albuquerque, Washington Silva, Wellington Pinheiro dos Santos · Research Square · 2022

Abstract Background and Objective: Almost all malwares running on web-server are php codes. Then, the present paper creates a NGAV (Next Generation Antivirus) expert in auditing threats web-based, specifically from php files, in real time. Methods: In our methodology, the malicious behaviors, of the personal computer, serve as input attributes of the statistical learning machines. In all, our dynamic feature extraction monitors 11,777 behaviors that the web fileless attack can do when launched directly from a malicious web-server to a listening service in a personal computer. Results: Our NGAV achieves an average 99.95% accuracy in the distinction between benign and malware web scripts. Distinct initial conditions and kernels of neural networks classifiers are investigated in order to maximize the accuracy of our NGAV. Conclusions: Our NGAV can supply the limitations of the commercial antiviruses as for the detection of Web fileless attack. In opposition of analysis of individual events, our engine employs authorial Web-server Sandbox, machine learning, and artificial intelligence in order to identify malicious Web-sites.

Read the paper · More papers on PaperTik