Fileless cyberattacks: Analysis and classification

Autor: GyungMin Lee, ShinWoo Shim, ByoungMo Cho, TaeKyu Kim, Kyounggon Kim
Jazyk: angličtina
Rok vydání: 2020
Předmět:
Zdroj: ETRI Journal, Vol 43, Iss 2, Pp 332-343 (2020)
Druh dokumentu: article
ISSN: 1225-6463
DOI: 10.4218/etrij.2020-0086
Popis: AbstractWith cyberattack techniques on the rise, there have been increasing developments in the detection techniques that defend against such attacks. However, cyber attackers are now developing fileless malware to bypass existing detection techniques. To combat this trend, security vendors are publishing analysis reports to help manage and better understand fileless malware. However, only fragmentary analysis reports for specific fileless cyberattacks exist, and there have been no comprehensive analyses on the variety of fileless cyberattacks that can be encountered. In this study, we analyze 10 selected cyberattacks that have occurred over the past five years in which fileless techniques were utilized. We also propose a methodology for classification based on the attack techniques and characteristics used in fileless cyberattacks. Finally, we describe how the response time can be improved during a fileless attack using our quick and effective classification technique.
Databáze: Directory of Open Access Journals