Building Detection-Resistant Reconnaissance Attacks Based on Adversarial Explainability
Mohammed M. Alani, Atefeh Mashatan, Ali Miri · 2024
The growing popularity of Internet-of-Things devices makes them a desired target for malicious actors. Most attacks start with a reconnaissance phase where the attacker gathers information about the services running on the device, the open ports, and any existing vulnerabilities. These attacks are considered the initial step in most attack scenarios, and threat models. However, these attacks are usually easy to detect using machine learning-based detectors due to their simple nature and easy construction. In this paper, we present a novel method to construct detection-resistant reconnaissance attacks based on analysis of detection model's explanability. The proposed attack was implemented with a success rate exceeding 95% in bypassing detection with the change of one feature only.