Early Detection of Fileless Attacks Based on Multi-Feature Fusion of Complex Attack Vectors

Tao Leng, Lixin Zhao, Yuedong Pan, Aimin Yu, Ziyuan Zhu, Lijun Cai, Dan Meng · 2024

The initial manifestations of fileless attacks were predominantly document-based attacks, extensively leveraged in Advanced Persistent Threat (APT) campaigns and cybercriminal activities. Malicious documents leveraging macros, DDE, template injection, and other attack vectors evade conventional signature-based detection techniques. Additionally, the constant influx of new samples undermines models trained only on single attack vector features. Herein, we introduce DocInspect, a methodological framework predicated on the multi-feature fusion of complex attack vectors. Through observational analyses of attack vectors, static analysis extracts keywords and indicators of compromise from vectors like macro code, simulated execution retrieves shellcode function calls and parameters, and deceptive images and text are concurrently extracted. These multi-dimensional features are then fused to construct feature vectors. Ultimately, leveraging the Extra Trees model on our latest sample set, we achieve an F1 score of 99.96%, while demonstrating commendable robustness.

Read the paper · More papers on PaperTik