Skip to main navigation Skip to search Skip to main content

A Memory Data Erasure Technique for Linux Shared Object

  • Gang Long
  • , Hanlin Yang
  • , Wei Wang
  • , Zhaoxin Zhang*
  • , Xiaolong Li
  • , Tengteng Zhao
  • , Jian Wang
  • , Wei Zhang
  • , Tingting Wang
  • , Tingyu Zhang
  • *Corresponding author for this work
  • Harbin Institute of Technology Weihai
  • Beijing Institute of Control and Electronic Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Fileless malware and in-memory-only malicious payloads have become a trend of cyberthreat. To perform a stealthy and traceless infiltration, threat actors and security researchers have presented several anti-forensic techniques for memory-resident payloads, mostly focusing on hiding the memory data from being detected by forensic tools. In this paper, we take another direction to think about erasing the artifact from the memory so no trace is left behind. We propose a self-deletion and self-unloading technique for a malicious payload compiled as a Linux shared object, to destruct its memory data when needed, which can be used in combination with in-memory execution and process injection techniques to launch a fileless and traceless attack. As is proved by the experiment, after the shared object containing the malicious payload is self-destructed using our technique, all its data are removed from the memory of the victim machine without any remains. To prevent its misuse, we also provide suggestions for system managers and incident responders on mitigating and detecting the abuse of this technique.

Original languageEnglish
Title of host publication2023 5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages78-81
Number of pages4
ISBN (Electronic)9798350309034
DOIs
StatePublished - 2023
Externally publishedYes
Event5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023 - Hybrid, Qingdao, China
Duration: 17 Nov 202319 Nov 2023

Publication series

Name2023 5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023

Conference

Conference5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023
Country/TerritoryChina
CityHybrid, Qingdao
Period17/11/2319/11/23

Keywords

  • antiforensics
  • fileless malware
  • memory data erasure
  • operating system security
  • shared object self-deletion
  • shared object self-unloading

Fingerprint

Dive into the research topics of 'A Memory Data Erasure Technique for Linux Shared Object'. Together they form a unique fingerprint.

Cite this