HESPIDS: A Hierarchical and Extensible System for Process Injection Detection using Sysmon

dc.contributor.authorThomas, Rodney
dc.contributor.authorSteiner, Stuart
dc.contributor.authorConte De Leon, Daniel
dc.date.accessioned2021-12-24T18:28:51Z
dc.date.available2021-12-24T18:28:51Z
dc.date.issued2022-01-04
dc.description.abstractAdvanced Persistent Threat (APT) actors are increasingly utilizing Living-off-the-Land (LotL) cyber attack techniques to avoid detection. LotL are techniques that abuse legitimate functionality to perform malicious cyber activities. A common LotL attack technique, that is currently very difficult to detect and prevent, is malicious process injection, MITRE ATT\&CK Process Injection ID: T1055. We report on the initial results for HESPIDS: A Hierarchical and Extensible System for Process Injection Detection using Sysmon. We developed a hierarchical graph-based detection approach for accurate and automated detection for five process injection techniques in Windows clients. These techniques include four of 11 T1055 sub-techniques: DLL Injection, PE Injection, APC Injection, Process Hollowing, and a T1056 sub-technique: API Hooking (T1056.004). Our novel detection approach exhibits, within the limitations of our small testing environment, very high sensitivity and specificity. HESPIDS demonstrates a promising avenue for development of automated detection of advanced cybersecurity threats.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2022.905
dc.identifier.isbn978-0-9981331-5-7
dc.identifier.urihttp://hdl.handle.net/10125/80247
dc.language.isoeng
dc.relation.ispartofProceedings of the 55th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Operations, Defence, and Forensics
dc.subjectadvanced persistant threats
dc.subjectliving off the land
dc.subjectprocess injection
dc.titleHESPIDS: A Hierarchical and Extensible System for Process Injection Detection using Sysmon
dc.type.dcmitext

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0735.pdf
Size:
925.79 KB
Format:
Adobe Portable Document Format