Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization
Muhammad Shoaib, Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul Hassan
摘要
Red teams require evasion techniques to test Security Information and Event Management (SIEM) detection rules, yet existing approaches are (1) manual, (2) rely on stringlevel obfuscations (such as encoding schemes and quoting tricks) that are easily reversed by de-obfuscators, and (3) provide limited rule coverage. This leaves unexplored semanticpreserving evasions that achieve identical effects through different utilities, preventing assessment of whether rules detect attack intent or merely surface patterns. We present Spectra, an automated evasion generator that preserves attack effects while transforming command-line realization through functionally equivalent utilities and argument structures. By reasoning over semantic representations rather than syntactic patterns, Spectra automatically generates more durable and effective evasions. On Windows Sigma process_creation rules, Spectra achieves 72.9 % rule coverage compared to 37.6 % for AMIDES (the state-of-the-art method), with only 4.5% of evasions reversed by de-obfuscators versus 78.1% for AMIDES (17.4 times more resistant). When evaluated against the state-of-the-art evasion detector at its zero-falsepositive operating point, Spectra achieves a detection rate of only 22.7 % compared to 69.9 % for AMIDES. SPECTRA also outperforms five general-purpose LLMs across metrics.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise NetworksRafael Uetz, Marco Herzog, Louis Hackländer, Simon Schwarz 等USENIX Security 2024 · 被引用 23 次
- From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat ReportsYongxin Cai, Jing Qiu, Qingming Li, Du Cheng 等USENIX Security 2026
- A Context Is Worth a Thousand Lies: Evading Intrusion Detectors via Intelligent Context DistortionMagdy Nasr, Vansh Rastogi, Azadeh TabibanBS&P 2026 · 被引用 1 次
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 被引用 1 次
- RulePilot: An LLM-Powered Agent for Security Rule GenerationHongtai Wang, Ming Xu, Yanpei Guo, Weili Han 等ICSE 2026 · 被引用 1 次
