面向Windows平台的样本对抗研究
电子技术应用
莫施文,沙乐天,潘家晔
南京邮电大学
摘要: 随着网络攻击技术的不断演进,针对企业和组织的高级持续性威胁(APT)攻击愈演愈烈。APT攻击的成功与否,很大程度上依赖于后渗透阶段的执行质量,在该阶段,攻击者利用复杂的对抗技术实现持久控制和数据窃取。围绕后渗透中的对抗技术展开,探讨了Bootkit、COM接口滥用、BYOVD、VEILP7等对抗技术,提出了一种新的对抗框架,并通过实验展示了其在多个反病毒工具中的对抗能力以及相对于现有对抗工具的优势,并针对该框架提出相应的对抗策略,旨在推动对抗技术的研究和防御机制的优化。
中图分类号:TP393.08 文献标志码:A DOI: 10.16157/j.issn.0258-7998.256460
中文引用格式: 莫施文,沙乐天,潘家晔. 面向Windows平台的样本对抗研究[J]. 电子技术应用,2025,51(10):52-57.
英文引用格式: Mo Shiwen,Sha Letian,Pan Jiaye. Adversarial research on malware samples for the Windows platform[J]. Application of Electronic Technique,2025,51(10):52-57.
中文引用格式: 莫施文,沙乐天,潘家晔. 面向Windows平台的样本对抗研究[J]. 电子技术应用,2025,51(10):52-57.
英文引用格式: Mo Shiwen,Sha Letian,Pan Jiaye. Adversarial research on malware samples for the Windows platform[J]. Application of Electronic Technique,2025,51(10):52-57.
Adversarial research on malware samples for the Windows platform
Mo Shiwen,Sha Letian,Pan Jiaye
Nanjing University of Posts and Telecommunications
Abstract: With the continuous evolution of cyberattack technologies, Advanced Persistent Threats (APT) targeting enterprises and organizations have become increasingly prevalent. The success of APT attacks largely depends on the execution quality during the post-exploitation phase, where attackers use sophisticated adversarial techniques to maintain persistent control and exfiltrate data. This paper focuses on adversarial techniques in the post-exploitation phase, discussing technologies such as Bootkit, COM Interface Abuse, BYOVD, and VEIL7, and introduces a new adversarial framework. Through experiments, the paper demonstrates its bypass capabilities against multiple antivirus tools, as well as its advantages over existing adversarial tools. Additionally, corresponding defense strategies for this framework are proposed to advance research on countermeasure techniques and optimize defense mechanisms.
Key words : APT attacks;adversarial techniques;Bootkit;COM interface exploitation;vulnerable driver
引言
近年来,随着网络攻击技术的不断演进,针对企业和组织的高级持续性威胁(Advanced Persistent Threat,APT)攻击愈演愈烈。APT攻击的成功与否,很大程度上依赖于后渗透阶段的执行质量,在后渗透阶段,攻击者利用复杂的对抗技术实现持久控制和数据窃取,然而,当前的防御系统在面对多种对抗技术时仍存在不足,如早期启动过程时的对抗,恶意利用合法接口和合法驱动时的对抗,多层级定制化框架时的对抗。本文提出了一种面向Windows平台的对抗框架,并测试其在实际对抗中的效果、效率,并对比同类软件,该框架展现出高对抗成功率、高执行效率以及更强的适用性,最后提出了针对该框架的应对策略,旨在推动对抗技术的研究和防御机制的优化。
本文详细内容请下载:
//www.51qz.net/resource/share/2000006806
作者信息:
莫施文,沙乐天,潘家晔
(南京邮电大学,江苏 南京 210023)

