Generic, efficient, and effective deobfuscation and semantic-aware attack detection for PowerShell scripts

被引:4
|
作者
Xiong, Chunlin [1 ]
Li, Zhenyuan [1 ]
Chen, Yan [2 ]
Zhu, Tiantian [3 ]
Wang, Jian [1 ]
Yang, Hai [4 ]
Ruan, Wei [5 ]
机构
[1] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310027, Peoples R China
[2] Northwestern Univ, Dept Elect Engn & Comp Sci, Evanston, IL 60208 USA
[3] Zhejiang Univ Technol, Coll Comp Sci & Technol, Hangzhou 310023, Peoples R China
[4] Mag Shield Co Ltd, Hangzhou 310027, Peoples R China
[5] Zhejiang Univ, Coll Control Sci & Engn, Hangzhou 310027, Peoples R China
基金
中国国家自然科学基金;
关键词
PowerShell; Abstract syntax tree; Obfuscation and deobfuscation; Malicious script detection; TP309;
D O I
10.1631/FITEE.2000436
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, PowerShell has increasingly been reported as appearing in a variety of cyber attacks. However, because the PowerShell language is dynamic by design and can construct script fragments at different levels, state-of-the-art static analysis based PowerShell attack detection approaches are inherently vulnerable to obfuscations. In this paper, we design the first generic, effective, and lightweight deobfuscation approach for PowerShell scripts. To precisely identify the obfuscated script fragments, we define obfuscation based on the differences in the impacts on the abstract syntax trees of PowerShell scripts and propose a novel emulation-based recovery technology. Furthermore, we design the first semantic-aware PowerShell attack detection system that leverages the classic objective-oriented association mining algorithm and newly identifies 31 semantic signatures. The experimental results on 2342 benign samples and 4141 malicious samples show that our deobfuscation method takes less than 0.5 s on average and increases the similarity between the obfuscated and original scripts from 0.5% to 93.2%. By deploying our deobfuscation method, the attack detection rates for Windows Defender and VirusTotal increase substantially from 0.33% and 2.65% to 78.9% and 94.0%, respectively. Moreover, our detection system outperforms both existing tools with a 96.7% true positive rate and a 0% false positive rate on average.
引用
收藏
页码:361 / 381
页数:21
相关论文
共 50 条
  • [1] Effective and light-weight deobfuscation and semantic-aware attack detection for powershell scripts
    Li, Zhenyuan
    Chen, Yan
    Chen, Qi Alfred
    Zhu, Tiantian
    Xiong, Chunlin
    Yang, Hai
    Proceedings of the ACM Conference on Computer and Communications Security, 2019, : 1831 - 1847
  • [2] Effective and Light-Weight Deobfuscation and Semantic-Aware Attack Detection for PowerShell Scripts
    Li, Zhenyuan
    Chen, Qi Alfred
    Xiong, Chunlin
    Chen, Yan
    Zhu, Tiantian
    Yang, Hai
    PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 1831 - 1847
  • [3] Generic, efficient, and effective deobfuscation and semantic-aware attack detection for PowerShell scripts通用、 有效且轻量的PowerShell解混淆和语义敏感的攻击检测方法
    Chunlin Xiong
    Zhenyuan Li
    Yan Chen
    Tiantian Zhu
    Jian Wang
    Hai Yang
    Wei Ruan
    Frontiers of Information Technology & Electronic Engineering, 2022, 23 : 361 - 381
  • [4] Power-ASTNN: A deobfuscation and AST neural network enabled effective detection method for malicious PowerShell Scripts
    Zhang, Sanfeng
    Li, Shangze
    Lu, Juncheng
    Yang, Wang
    COMPUTERS & SECURITY, 2025, 154
  • [5] Efficient Semantic-Aware Detection of Near Duplicate Resources
    Ioannou, Ekaterini
    Papapetrou, Odysseas
    Skoutas, Dimitrios
    Nejdl, Wolfgang
    SEMANTIC WEB: RESEARCH AND APPLICATIONS, PT 2, PROCEEDINGS, 2010, 6089 : 136 - 150
  • [6] Semantic-Aware Vulnerability Detection
    Huang, Zhen
    White, Marc
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 68 - 75
  • [7] Semantic-Aware Video Text Detection
    Feng, Wei
    Yin, Fei
    Zhang, Xu-Yao
    Liu, Cheng-Lin
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 1695 - 1705
  • [8] Semantic-aware Transformer for shadow detection
    Zhou, Kai
    Fang, Jing-Long
    Wu, Wen
    Shao, Yan-Li
    Wang, Xing-Qi
    Wei, Dan
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2024, 240
  • [9] Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images
    Schaffhauser, Andreas
    Mazurczyk, Wojciech
    Caviglione, Luca
    Zuppelli, Marco
    Hernandez-Castro, Julio
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [10] Efficient Semantic-Aware TSDF Mapping with Adaptive Resolutions
    Wang, Weidong
    Hu, Yu
    Xi, Wei
    Zou, Danping
    Yu, Wenxian
    2023 3RD INTERNATIONAL CONFERENCE ON ROBOTICS, AUTOMATION AND ARTIFICIAL INTELLIGENCE, RAAI 2023, 2023, : 39 - 45