Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Articolo
Data di Pubblicazione:
2022
Abstract:
Due to steady improvements in defensive systems, malware developers are turning their attention to mechanisms for cloaking attacks as long as possible. A recent trend exploits techniques like Invoke-PSImage, which allows embedding a malicious script within an innocent-looking image, for example, to smuggle data into compromised devices. To address such a class of emerging threats, new mechanisms are needed, since standard tools fail in their detection or offer poor performance. To this aim, this work introduces Mavis, an efficient and highly accurate method for detecting hidden payloads, retrieving the embedded information, and estimating its size. Experimental results collected by considering real-world malicious PowerShell scripts showcase that Mavis can detect attacks with a high accuracy (100%) while keeping the rate of false positives and false negatives very low (0.01% and 0%, respectively). The proposed approach outperforms other solutions available in the literature or commercially through "as a service" model.
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
information hiding; steganography; stegomalware; cybersecurity
Elenco autori:
Zuppelli, Marco; Caviglione, Luca
Autori di Ateneo:
CAVIGLIONE LUCA
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/414343
Pubblicato in:
SECURITY AND COMMUNICATION NETWORKS (ONLINE)
Journal
  • Dati Generali

Dati Generali

URL

https://www.hindawi.com/journals/scn/2022/4477317/#copyright
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)