상세 보기
프로세스 가상 메모리 데이터 유사성을 이용한 프로세스 할로윙 공격 탐지
- 임수민;
- 임을규
초록
Fileless malware uses memory injection attacks to hide traces of payloads to perform malicious works. During thememory injection attack, an attack named “process hollowing” is a method of creating paused benign process like systemprocesses. And then injecting a malicious payload into the benign process allows malicious behavior by pretending to be anormal process. In this paper, we propose a method to detect the memory injection regardless of whether or not the malicious action isactually performed when a process hollowing attack occurs. The replication process having same execution condition as theprocess of suspending the memory injection is executed, the data set belonging to each process virtual memory area iscompared using the fuzzy hash, and the similarity is calculated.
키워드
- 제목
- 프로세스 가상 메모리 데이터 유사성을 이용한 프로세스 할로윙 공격 탐지
- 제목 (타언어)
- Proposal of Process Hollowing Attack Detection Using Process Virtual Memory Data Similarity
- 저자
- 임수민; 임을규
- 발행일
- 2019-04
- 저널명
- 정보보호학회논문지
- 권
- 29
- 호
- 2
- 페이지
- 431 ~ 438