پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

ارائه الگوی شناسایی روتکیت‌های سطح کاربر با استفاده از بررسی و ردیابی فراخوانی سیستمی

نوع مقاله : مقاله پژوهشی

نویسنده
استادیار ،دانشگاه جامع امام حسین( ع)، تهران ، ایران
چکیده
توسعه‌دهندگان بدافزار، امروزه با روش‌های نوین، اقدام به دور زدن راهکارهای امنیتی در نقطه پایانی می‌کنند. قلاب توابع سیستمی در سطح هسته، به‌دلیل وجود پچ‌گارد، عملی دشوار و غیرممکن است. امروز توسعه‌دهندگان بدافزار، به‌صورت کلی از چهار روش به‌منظور اجتناب از رهگیری توسط قلاب استفاده می‌کنند. عمل رهاسازی قلاب و وصله توابع قلاب‌شده، رویکردی مشابه در اجرا دارند. این تحقیق، با استفاده از محاسبه دوره‌ای یا عملکرد بازگشتی و مطابقت با مقدار اولیه، اقدام به شناسایی این ویژگی‌ها می‌کند. در صورت تغییر مقدار بایت حافظه و تغییر جامعیت نخست، اقدام به تولید هشدار می‌کند. به‌منظور تشخیص فراخوانی مستقیم، ابتدا باید دستورالعمل سیسکال درون فضای آدرس پردازه مشخص شود. در صورت فراخوانی دستورالعمل سیسکال درون فضای کد پردازه، باید هشدار لازم را تولید کرد. شناسایی حمله فراخوانی غیر مستقیم، نیازمند بازیابی تماس پشته است. در صورت مغایرت در آدرس‌های تماس پشته با آدرس بازگشتی از سمت هسته، باید این عمل را مخرب در نظر گرفت. به‌منظور ارزیابی، جعبه شن یا ماتوس با چند محصول تجاری از جمله راهکار نقطه پایانی سوفوس، کرود استرایک، اوست، ترند میکرو مقایسه می‌شود. در این تحقیق، تعداد 40 پرونده اجرایی به تفکیک 20 روتکیت سطح کاربر و 20 نرم‌افزار سالم به‌منظور آزمایش در نظر گرفته شده‌اند. در نهایت، با بررسی درصد مثبت واقعی و منفی کاذب روش اجرا شده در این تحقیق، اثبات می‌شود که نتایج دقت محصول سوفوس 63/0، کرود استرایک 70/0، اوست 58/0، ترند میکرو 58/0 است. ماتوس توانسته تعداد 17 روتکیت سطح کاربر از 20 روتکیت را به درستی تشخیص دهد. در ادامه این مقایسه دقت جعبه شن در تشخیص بدافزارها 93/0 بوده که با بالاترین دقت تشخیص یعنی کرود استرایک به مقدار 32/0 بهبود یافته است.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Presenting a model for detecting user-level rootkits using system call monitoring and tracing

نویسنده English

Hamid Akbari
Assistant Professor, Imam Hossein (AS) University, Tehran, Iran
چکیده English

Today, malware developers use new methods to circumvent security solutions at the endpoint. Hooking system functions at the kernel level is difficult and impossible due to the presence of patchguard. Today, malware developers generally use four methods to avoid detection by hooks. Unhooking and patching of hooked functions have a similar approach in implementation. This research tries to identify these features by using periodic calculation or recursive function and corresponding to the initial value. If the memory byte value is changed and the first completeness is changed, it will generate a warning. In order to detect a direct call, first the syscall instruction must be specified in the address space of the processor. If the syscall instruction is called inside the process code space, the necessary warning should be generated. Detecting an indirect call attack requires call stack recovery. If there is a discrepancy between the call stack addresses and the return address from the kernel side, this action should be considered malicious. In order to evaluate, Sandbox or Matos is compared with several commercial products including Sophos endpoint solution, Crowdstrike, Ost, Trend Micro. In this research, the number of 40 executable files separated by 20 user-level rootkits and 20 healthy software are considered for testing. Finally, by examining the percentage of true positives and false negatives of the method implemented in this research, it is proved that the accuracy results of Sophos product are 0.63, Crowdstrike 0.70, Ost 0.58, Trend Micro 0.58. Matos was able to correctly identify 17 user-level rootkits out of 20 rootkits. In the continuation of this comparison, the accuracy of the sandbox in detecting malware is 0.93, which is improved by 0.32 with the highest detection accuracy, i.e. Crowd Strike.

کلیدواژه‌ها English

User-level rootkit
calling system functions
unhooking
hooking system functions
endpoint solution

مقالات آماده انتشار، پذیرفته شده
انتشار آنلاین از 01 شهریور 1405

  • تاریخ دریافت 16 فروردین 1405
  • تاریخ بازنگری 13 مرداد 1405
  • تاریخ پذیرش 19 مرداد 1405
  • تاریخ انتشار 01 شهریور 1405