ShadowMove: A Stealthy Lateral Movement Strategy
Amirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang, Bei-Tseng Chu
摘要
Advanced Persistence Threat (APT) attacks use various strategies and techniques to move laterally within an enterprise environment; however, the existing strategies and techniques have limitations such as requiring elevated permissions, creating new connections, performing new authentications, or requiring process injections. Based on these characteristics, many host and network-based solutions have been proposed to prevent or detect such lateral movement attempts. In this paper, we present a novel stealthy lateral movement strategy, ShadowMove, in which only established connections between systems in an enterprise network are misused for lateral movements. It has a set of unique features such as requiring no elevated privilege, no new connection, no extra authentication, and no process injection, which makes it stealthy against stateof-the-art detection mechanisms. ShadowMove is enabled by a novel socket duplication approach that allows a malicious process to silently abuse TCP connections established by benign processes. We design and implement ShadowMove for current Windows and Linux operating systems. To validate the feasibility of ShadowMove, we build several prototypes that successfully hijack three kinds of enterprise protocols, FTP, Microsoft SQL, and Window Remote Management, to perform lateral movement actions such as copying malware to the next target machine and launching malware on the target machine. We also confirm that our prototypes cannot be detected by existing host and network-based solutions, such as five top-notch anti-virus products (McAfee, Norton, Webroot, Bitdefender, and Windows Defender), four IDSes (Snort, OS-SEC, Osquery, and Wazuh), and two Endpoint Detection and Response systems (CrowdStrike Falcon Prevent and Cisco AMP).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson 等USENIX Security 2021 · 被引用 41 次
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 被引用 14 次
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu 等USENIX Security 2024 · 被引用 9 次
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman 等USENIX Security 2026
它引用的顶会 Paper4
- Detecting Structurally Anomalous Logins Within Enterprise NetworksHossein Siadati, Nasir D. MemonCCS 2017 · 被引用 44 次
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 被引用 35 次
- Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the ComputerThanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan 等USENIX Security 2018 · 被引用 25 次
- The Secure Socket API: TLS as an Operating System ServiceMark O'Neill, Scott Heidbrink, Jordan Whitehead, Tanner Perdue 等USENIX Security 2018 · 被引用 20 次
相关 Paper
- You Are What You Do: Hunting Stealthy Malware via Data Provenance AnalysisQi Wang, Wajih Ul Hassan, Ding Li, Kangkook Jee 等NDSS 2020
- Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise NetworksJoseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra 等S&P 2024 · 被引用 28 次
- EvilEDR: Repurposing EDR as an Offensive ToolKotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten 等USENIX Security 2025
- Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningWei Qiao, Yebo Feng, Teng Li, Zhuo Ma 等CCS 2025 · 被引用 1 次
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens 等NDSS 2020
