TY - GEN
T1 - A Memory Data Erasure Technique for Linux Shared Object
AU - Long, Gang
AU - Yang, Hanlin
AU - Wang, Wei
AU - Zhang, Zhaoxin
AU - Li, Xiaolong
AU - Zhao, Tengteng
AU - Wang, Jian
AU - Zhang, Wei
AU - Wang, Tingting
AU - Zhang, Tingyu
N1 - Publisher Copyright:
© 2023 IEEE.
PY - 2023
Y1 - 2023
N2 - Fileless malware and in-memory-only malicious payloads have become a trend of cyberthreat. To perform a stealthy and traceless infiltration, threat actors and security researchers have presented several anti-forensic techniques for memory-resident payloads, mostly focusing on hiding the memory data from being detected by forensic tools. In this paper, we take another direction to think about erasing the artifact from the memory so no trace is left behind. We propose a self-deletion and self-unloading technique for a malicious payload compiled as a Linux shared object, to destruct its memory data when needed, which can be used in combination with in-memory execution and process injection techniques to launch a fileless and traceless attack. As is proved by the experiment, after the shared object containing the malicious payload is self-destructed using our technique, all its data are removed from the memory of the victim machine without any remains. To prevent its misuse, we also provide suggestions for system managers and incident responders on mitigating and detecting the abuse of this technique.
AB - Fileless malware and in-memory-only malicious payloads have become a trend of cyberthreat. To perform a stealthy and traceless infiltration, threat actors and security researchers have presented several anti-forensic techniques for memory-resident payloads, mostly focusing on hiding the memory data from being detected by forensic tools. In this paper, we take another direction to think about erasing the artifact from the memory so no trace is left behind. We propose a self-deletion and self-unloading technique for a malicious payload compiled as a Linux shared object, to destruct its memory data when needed, which can be used in combination with in-memory execution and process injection techniques to launch a fileless and traceless attack. As is proved by the experiment, after the shared object containing the malicious payload is self-destructed using our technique, all its data are removed from the memory of the victim machine without any remains. To prevent its misuse, we also provide suggestions for system managers and incident responders on mitigating and detecting the abuse of this technique.
KW - antiforensics
KW - fileless malware
KW - memory data erasure
KW - operating system security
KW - shared object self-deletion
KW - shared object self-unloading
UR - https://www.scopus.com/pages/publications/85188090919
U2 - 10.1109/ICFTIC59930.2023.10455850
DO - 10.1109/ICFTIC59930.2023.10455850
M3 - 会议稿件
AN - SCOPUS:85188090919
T3 - 2023 5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023
SP - 78
EP - 81
BT - 2023 5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 5th International Conference on Frontiers Technology of Information and Computer, ICFTIC 2023
Y2 - 17 November 2023 through 19 November 2023
ER -