Living-off-the-Land Abuse Detection Using Natural Language Processing and Supervised Learning

08/26/2022
by   Ryan Stamp, et al.
0

Living-off-the-Land is an evasion technique used by attackers where native binaries are abused to achieve malicious intent. Since these binaries are often legitimate system files, detecting such abuse is difficult and often missed by modern anti-virus software. This paper proposes a novel abuse detection algorithm using raw command strings. First, natural language processing techniques such as regular expressions and one-hot encoding are utilized for encoding the command strings as numerical token vectors. Next, supervised learning techniques are employed to learn the malicious patterns in the token vectors and ultimately predict the command's label. Finally, the model is evaluated using statistics from the training phase and in a virtual environment to compare its effectiveness at detecting new commands to existing anti-virus products such as Windows Defender.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/30/2021

Living-Off-The-Land Command Detection Using Active Learning

In recent years, enterprises have been targeted by advanced adversaries ...
research
08/19/2019

Automated email Generation for Targeted Attacks using Natural Language

With an increasing number of malicious attacks, the number of people and...
research
08/26/2020

Understanding scholarly Natural Language Processing system diagrams through application of the Richards-Engelhardt framework

We utilise Richards-Engelhardt framework as a tool for understanding Nat...
research
03/15/2022

TSM: Measuring the Enticement of Honeyfiles with Natural Language Processing

Honeyfile deployment is a useful breach detection method in cyber decept...
research
09/09/2022

Improving Model Training via Self-learned Label Representations

Modern neural network architectures have shown remarkable success in sev...
research
03/01/2021

Token-Modification Adversarial Attacks for Natural Language Processing: A Survey

There are now many adversarial attacks for natural language processing s...
research
04/11/2018

Detecting Malicious PowerShell Commands using Deep Neural Networks

Microsoft's PowerShell is a command-line shell and scripting language th...

Please sign up or login with your details

Forgot password? Click here to reset