Lune

USENIX Security2021顶会

Forecasting Malware Capabilities From Cyber Attack Memory Images

Omar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi, Srimanta Barua, Taleb Hirani, Brennan Hill, Brendan Saltaformaggio

出版方
2021年份
32被引次数
10顶会引用

摘要

The remediation of ongoing cyber attacks relies upon timely malware analysis, which aims to uncover malicious functionalities that have not yet executed. Unfortunately, this requires repeated context switching between different tools and incurs a high cognitive load on the analyst, slowing down the investigation and giving attackers an advantage. We present Forecast, a post-detection technique to enable incident responders to automatically predict capabilities which malware have staged for execution. Forecast is based on a probabilistic model that allows Forecast to discover capabilities and also weigh each capability according to its relative likelihood of execution (i.e., forecasts). Forecast leverages the execution context of the ongoing attack (from the malware's memory image) to guide a symbolic analysis of the malware's code. We performed extensive evaluations, with 6,727 real-world malware and futuristic attacks aiming to subvert Forecast, showing the accuracy and robustness in predicting malware capabilities. on this idea, we propose seeding the symbolic exploration of a malware's pre-staged paths with concrete execution state obtained via memory image forensics. Through this, we overcome the previous painstaking and cognitively burdensome process that an analyst must undertake. We present Forecast, a post-detection technique to enable incident responders to forecast what capabilities are possible from a captured memory image. Forecast ranks each discovered capability according to its probability of execution (i.e., forecasts) to enable analysts to prioritize their remediation workflows. To calculate this probability, Forecast weighs each path's relative usage of concrete data. This approach is based on a formal model of the degree of concreteness (or D C (s)) of a memory image execution state (s). Starting from the last instruction pointer (IP) value in the memory image, Forecast explores each path by symbolically executing the CPU semantics of each instruction. During this exploration, Forecast models how the mixing of symbolic and concrete data influences path generation and selection. Based on this mixing, a "concreteness" score is calculated for each state along a path to derive forecast percentages for each discovered capability. D C (s) also optimizes symbolic analysis by dynamically adapting loop bounds, handling symbolic control flow, and pruning paths to reduce path explosion. To automatically identify each capability, we developed several modular capability analysis plugins: Code Injection, File Exfiltration, Dropper, Persistence, Key & Screen Spying, Anti-Analysis, and C&C URL Connection. Each plugin defines a given capability in terms of API sequences, their arguments, and how their input and output constraints connect each API. Forecast plugins are portable and can easily be extended to capture additional capabilities based on the target system's APIs. It is worth noting that Forecast's analysis only requires a forensic memory image, allowing it to work for fileless malware, making it well-suited for incident response. We evaluated Forecast with memory images of 6,727 real-world malware (including packed and unpacked) covering 274 families. Forecast renders accurate capability forecasts compared to reports produced manually by human experts. Further, we show that Forecast is robust against futuristic attacks that aim to subvert Forecast. We show that Forecast's post-detection forecasts are accurately induced by early concrete inputs. We empirically compared Forecast to S2E [6], angr [22], and Triton [23] and found that Forecast outperforms them in identifying capabilities and reducing path explosion. Forecast is available online at: https://cyfi.ece.gatech.edu/ .

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper10

问问它们各自怎么用它

它引用的顶会 Paper10

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖