Effective Malicious PowerShell Scripts Detection Using DistilBERT
Ahmed Yasser Merzouk Benselloua, Said Abdesslem Messadi, Alaa Eddine Belfedhal · 2023
Malicious PowerShell scripts have become a prominent vector for cyberattacks, necessitating the development of efficient detection methods to mitigate associated risks. This research paper presents an innovative approach for the detection of malicious PowerShell scripts using the DistilBERT model, a distilled variant of the BERT architecture. Leveraging the power of transformer-based language models, our method capitalizes on the inherent ability of DistilBERT to capture intricate contextual and semantic information within scripts. Through extensive experimentation on a unique dataset containing diverse malicious and benign scripts, we demonstrate the effectiveness of our approach. Our model achieves superior accuracy, precision, and recall, while also maintaining a low false positive rate. This study not only showcases the potential of large language models for cybersecurity tasks but also contributes a robust solution to the real-world challenge of malicious script detection, paving the way for enhanced cybersecurity measures.