Effective and Light-Weight Deobfuscation and Semantic-Aware Attack Detection for PowerShell Scripts
Zhenyuan Li, Qi Alfred Chen, Chunlin Xiong, Yan Chen, Tiantian Zhu, Hai Yang
Abstract
In recent years, PowerShell is increasingly reported to appear in a variety of cyber attacks ranging from advanced persistent threat, ransomware, phishing emails, cryptojacking, financial threats, to fileless attacks. However, since the PowerShell language is dynamic by design and can construct script pieces at different levels, state-ofthe-art static analysis based PowerShell attack detection approaches are inherently vulnerable to obfuscations. To overcome this challenge, in this paper we design the first effective and light-weight deobfuscation approach for PowerShell scripts. To address the challenge in precisely identifying the recoverable script pieces, we design a novel subtree-based deobfuscation method that performs obfuscation detection and emulation-based recovery at the level of subtrees in the abstract syntax tree of PowerShell scripts. Building upon the new deobfuscation method, we are able to further design the first semantic-aware PowerShell attack detection system. To enable semantic-based detection, we leverage the classic objective-oriented association mining algorithm and newly identify 31 semantic signatures for PowerShell attacks. We perform an evaluation on a collection of 2342 benign samples and 4141 malicious samples, and find that our deobfuscation method takes less than 0.5 seconds on average and meanwhile increases the similarity between the obfuscated and original scripts from only 0.5% to around 80%, which is thus both effective and light-weight. In addition, with our deobfuscation applied, the attack detection rates for Windows Defender and VirusTotal increase substantially from 0.3% and 2.65% to 75.0% and 90.0%, respectively. Furthermore, when our deobfuscation is applied, our semantic-aware attack detection system outperforms both Windows Defender and VirusTotal with a 92.3% true positive rate and a 0% false positive rate on average. CCS CONCEPTS • Security and privacy → Malware and its mitigation; Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandFrederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor et al.S&P 2021 · 73 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- PowerPeeler: A Precise and General Dynamic Deobfuscation Method for PowerShell ScriptsRuijie Li, Chenyang Zhang, Huajun Chai, Lingyun Ying et al.CCS 2024 · 3 citations
- Sharing cyber threat intelligence: Does it really help?Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino et al.NDSS 2024
Related papers
- PSDissect: A CFG-Guided, Semantics-Preserving Interactive Deobfuscation Framework for PowerShell ScriptsYifeng Fu, Jingfeng Xue, Weijie Han, Yong Wang et al.CCS 2026
- Analyzing PDFs like Binaries: Adversarially Robust PDF Malware Analysis via Intermediate Representation and Language ModelSide Liu, Jiang Ming, Guodong Zhou, Xinyi Liu et al.CCS 2025
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
- WasmGuard: Enhancing Web Security through Robust Raw-Binary Detection of WebAssembly MalwareYuxia Sun, Huihong Chen, Zhixiao Fu, Wenjian Lv et al.WWW 2025 · 2 citations
- MINOS: A Lightweight Real-Time Cryptojacking Detection SystemFaraz Naseem Naseem, Ahmet Aris, Leonardo Babun, Ege Tekiner et al.NDSS 2021
