Enhancing Linux System Security: A Kernel-Based Approach to Fileless Malware Detection and Mitigation

Author:

Wu Min-Hao1ORCID,Hsu Fu-Hau2ORCID,Huang Jian-Hung2,Wang Keyuan2ORCID,Hwang Yan-Ling3,Wang Hao-Jyun2,Chen Jian-Xin2,Hsiao Teng-Chuan2,Yang Hao-Tsung2ORCID

Affiliation:

1. College of Artificial Intelligence, Xiamen City University, Xiamen 361000, China

2. Department of Computer Science and Information Engineering, National Central University, Taoyuan 32001, Taiwan

3. Department of Applied Foreign Languages, Chung Shan Medical University, Taichung 40201, Taiwan

Abstract

In the late 20th century, computer viruses emerged as powerful malware that resides permanently in target hosts. For a virus to function, it must load into memory from persistent storage, such as a file on a hard drive. Due to the significant destructive potential of viruses, numerous defense measures have been developed to protect computer systems. Among these, antivirus software is one of the most recognized and widely used. Typically, antivirus solutions rely on static analysis (signature-based) technologies to detect infections in files stored on permanent storage devices, such as hard drives or USB (Universal Serial Bus) flash drives. However, a new breed of malware, fileless malware, has been designed to evade detection and enhance durability. Fileless malware resides solely in the memory of the target hosts, circumventing traditional antivirus software, which cannot access or analyze processes executed directly from memory. This study proposes the Check-on-Execution (CoE) kernel-based approach to detect fileless malware on Linux systems. CoE intervenes by suspending code execution before a program executes code from a process’s writable and executable memory area. To prevent the execution of fileless malware, CoE extracts the code from memory, packages it with an ELF (Executable and Linkable Format) header to create an ELF file, and uses VirusTotal for analysis. Experimental results demonstrate that CoE significantly enhances a Linux system’s ability to defend against fileless malware. Additionally, CoE effectively protects against shell code injection attacks, including buffer and memory overflows, and can handle packed malware. However, it is important to note that this study focuses exclusively on fileless malware, and further research is needed to address other types of malware.

Funder

Taiwan’s Ministry of Science and Technology

Publisher

MDPI AG

Reference18 articles.

1. Alzuri, A., Andrade, D.C., Escobar, Y.N., and Zamora, B.M. (2024, September 05). The growth of fileless malware. Available online: https://www.semanticscholar.org/paper/The-Growth-of-Fileless-Malware-Alzuri-Andrade/2e58298eda935452d7009ea440c838b9fc1a5658https://www.semanticscholar.org/paper/The-Growth-of-Fileless-Malware-Alzuri-Andrade/2e58298eda935452d7009ea440c838b9fc1a5658.

2. Rayome, A.D. (2024, September 05). Report: Fileless Malware Attacks 10× More Likely to Infect Your Machine than Others. Available online: https://www.enisa.europa.eu/publications/report-files/ETL-translations/fr/etl2020-malware-ebook-en-fr.pdf.

3. WatchGudrd (2024, September 05). New Research: Fileless Malware Attacks Surge by 900% and Cryptominers Make a Comeback, While Ransomware Attacks Decline. Available online: https://www.globenewswire.com/en/newsrelease/2021/03/30/2201173/0/en/New-Research-Fileless-Malware-Attacks-Surge-by-900-and-Cryptominers-Make-a-Comeback-While-Ransomware-Attacks-Decline.html.

4. Nick, B. (2024, September 05). Fileless Attack Detection for Linux in Preview. Available online: https://azure.microsoft.com/zh-tw/blog/filelessattack-detection-for-linux-in-preview/.

5. Stuart (2024, September 05). In-Memory-Only Elf Execution (without Tmpfs). Available online: https://magisterquis.github.io/2018/03/31/in-memory-only-elfexecution.html.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3