Title
IMShell-Dec - Pay More Attention to External Links in PowerShell.
Abstract
Windows proposes the PowerShell shell command line to substitute the traditional CMD. However, it is often utilized by the attacker to invade the victim because of its versatile functionality. In this paper, we investigate an attack combined PowerShell and image steganography. Compared with the traditional method, this attack can deceive the defender by hiding its malicious contents in benign images. To effectively detect this attack, we propose a framework IMShell-Dec, whose main target is to check external links before the execution of PowerShell script. IMShell-Dec trains a machine learning classifier with image examples, where the features are generated by merging histograms of three image color channels. Then IMShell-Dec examines the script through tracking and classifying the related images. The detector achieves more than 95% precision in 9,589 high-definition images.
Year
DOI
Venue
2020
10.1007/978-3-030-58201-2_13
SEC
DocType
Citations 
PageRank 
Conference
1
0.39
References 
Authors
0
6
Name
Order
Citations
PageRank
Ruidong Han110.39
C. Yang229643.66
Jianfeng Ma3120789.64
Siqi Ma410.39
YunBo Wang510.39
Feng Li610.39