PowerShell Malware Analysis Using a Novel Malware Rating System
David Arnold, Charlotte C. David, Jafar Saniie
Abstract
David Arnold, Charlotte C. David, Jafar Saniie
Abstract
Recent high-profile cyberattacks highlight an increased use of social engineering attacks and ransomware by hackers worldwide. These attacks target human operators directly, bypassing many of the cyber-safeguards developed through years of malware analysis. In response to these challenges, many organizations have turned to white-hat hackers and penetration testing to identify potential weaknesses and reinforce cyber-safety protocols. To assist in the threat evaluation process, malware rating systems are often used to highlight the danger and potential damage malware may cause. Current malware rating systems focus on assigning a danger score for malware based on its ability to move throughout the network, damage system resources, and evade detection. Due to the increased reliance on social engineering, a new malware rating system is proposed that incorporates malware deceitfulness as a means to trick human operators. The novel rating system will score malware based on its Stealth, Ease of Creation, Deceitfulness, Versatility, Instantaneousness, and Persistence. This system provides operators with insight into each key characteristics as opposed to a single value. To showcase the malware evaluation process, different PowerShell Reverse Bind Shell malwares are rated based on the proposed criteria.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Recent high-profile cyberattacks highlight an increased use of social engineering attacks and ransomware by hackers worldwide. These attacks target human operators directly, bypassing many of the cyber-safeguards developed through years of malware analysis. In response to these challenges, many organizations have turned to white-hat hackers and penetration testing to identify potential weaknesses and reinforce cyber-safety protocols. To assist in the threat evaluation process, malware rating systems are often used to highlight the danger and potential damage malware may cause. Current malware rating systems focus on assigning a danger score for malware based on its ability to move throughout the network, damage system resources, and evade detection. Due to the increased reliance on social engineering, a new malware rating system is proposed that incorporates malware deceitfulness as a means to trick human operators. The novel rating system will score malware based on its Stealth, Ease of Creation, Deceitfulness, Versatility, Instantaneousness, and Persistence. This system provides operators with insight into each key characteristics as opposed to a single value. To showcase the malware evaluation process, different PowerShell Reverse Bind Shell malwares are rated based on the proposed criteria.
Key concepts: Malware, Hacker, Computer security, Computer science, Cryptovirology, Malware analysis, Process (computing), Ransomware