Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “malware”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Malware Analysis Report for SolarWinds.Orion.Core.BusinessLayer.dll

SolarWinds Orion is a software suite designed to provide “single pane of glass” monitoring of network devices and applications. On December 13 2020, FireEye revealed that SolarWinds Orion was the victim of a supply chain attack and that the SolarWinds signed file SolarWinds.Orion.Core.BusinessLayer.dll contained a backdoor. SolarWinds deployed the back-doored patch to customers beginning in March 2020. FireEye first identified this backdoor and labeled it SUNBURST. The backdoor is composed of roughly 4,000 lines1 of lightly obfuscated .NET within the SolarWinds.Orion.Core.BusinessLayer.OrionImprovementBusinessLayer class of the malicious dll. The backdoor’s capabilities include: the ability to detect and potentially disable antivirus and forensics tools, basic command and control via DNS, and more advanced command and control via HTTP.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Rootkit detection system

A system and method (referred to as the system) detect infectious code. The system injects a repetitive software code that causes malware in a monitored device to render a detectable direct current power consumption profile. A guide wave generator generates a guide wave signal that establishes an observational window that is applied to data that represent a direct current source power consumption of the monitored device. An extraction device extracts a portion of the data that represent the direct current source power consumption of the monitored device. A deviation engine identifies the malware on the monitored device without processing data associated with a prior identification of the malware or identifying a source of the malware or identifying a location of the malware on the monitored device.

Dawson, Joel↗

Experimental Validation of a Command and Control Traffic Detection Model

Network intrusion detection systems (NIDS) are commonly used to detect malware communications, including command-and-control (C2) traffic from botnets. NIDS performance assessments have been studied for decades, but mathematical modeling has rarely been used to explore NIDS performance. This paper details a mathematical model that describes a NIDS performing packet inspection and its detection of malware's C2 traffic. Here, the paper further describes an emulation testbed and a set of cyber experiments that used the testbed to validate the model. These experiments included a commonly used NIDS (Snort) and traffic with contents from a pervasive malware (Emotet). Results are presented for two scenarios: a nominal scenario and a “stressed” scenario in which the NIDS cannot process all incoming packets. Model and experiment results match well, with model estimates mostly falling within 95 % confidence intervals on the experiment means. Model results were produced 70-3000 times faster than the experimental results. Consequently, the model's predictive capability could potentially be used to support decisions about NIDS configuration and effectiveness that require high confidence results, quantification of uncertainty, and exploration of large parameter spaces. Furthermore, the experiments provide an example for how emulation testbeds can be used to validate cyber models that include stochastic variability.

mathematical model↗

Toward the Detection of Polyglot Files

Standardized file types play a key role in the development and use of computer software. However, it is possible to confound standardized file type processing by creating a file that is valid in multiple file types. The resulting polyglot (many languages) file can confuse file type identification, allowing elements of the file to evade analysis. This is especially problematic for malware detection systems that rely on file type identification for feature extraction. Although work has been done to identify file types using more comprehensive methods than file signatures, accurate identification of polyglot files remains an open problem. Since malware detection systems routinely perform file type-specific feature extraction, polyglot files need to be filtered out prior to ingestion by these systems. Otherwise, malicious content could pass through undetected. To address the problem of polyglot detection we assembled a data set using the mitra tool. We then evaluated the performance of the most commonly used file identification tools, including file, polydet, binwalk, and TrID. Our analysis demonstrates that existing file type detection tools fail to provide reliable polyglot detection. We then evaluated the ability of a range of machine and deep learning models to detect polyglot files. The most performant models were MalConv2 and Catboost, which demonstrated the highest recall on our data set with 95.16% and 95.45%, respectively. These models outperformed existing methods and could be incorporated into a malware detector’s file processing pipeline to filter out potentially malicious polyglots before file type-dependent feature extraction takes place.

Koch, Luke↗