HITB-Invoice-Logo

thank you for joining us!

Scripts-behavioral ML Classification Using Windows 10 AMSI-instrumentation

Date

August 26, 2022

Time

11:30

Track

Main Track

As browser and operating system security have been improving, there has been a decline in conventional drive-by exploit attacks and a rise in social-engineering based attacks instead. One of the main types of social engineering attacks employs emails with attached archives containing script-based malware loaders or macro attachments. Usually these scripts are JavaScript, Visual Basic Script,Macro Documents or HTA files. If a user opens one of these scripts, the script will be hosted with a Windows script execution engine and usually proceeds to download and run malware such as ransomware. Traditional AV signature-based approaches to these attacks are often not practical since the time from a new email attack campaign starting to signature release is not fast enough. Machine learning is needed to effectively address this issue.

In this presentation we will be presenting how machine learning can be applied to detect and stop the execution of already-running malicious scripts on Windows using a feature called AMSI. Versions of Windows 10 have AMSI script integration where the Windows script execution engines monitor script calls to COM interfaces during execution and passes this information to the default installed security product for scanning. Security products can access these logs and make a blocking decision that will abort the execution of the script. Firstly, we will present details on how the AMSI integration works and what these logs look like for malicious scripts. Next, we will present research on how MLย  models can be used to classify malicious script behavior. And finally, we will present a more practical approach weโ€™ve deployed using lightweight client models paired with heavy cloud models to deliver protection from these malicious scripts in real-time during execution.

Speakers

Researcher

National University Singapore

Dr. Wang Kailong is currently a research fellow at National University of Singapore (NUS). He received his PhD degree from School of Computing NUS in 2022. He has worked as a Research Assistant in NUS while pursuing his PhD degree from 2016 to 2021. His research interests include mobile and web security and privacy, and protocol verification. His works have appeared in the top conferences such as WWW and MobiCom.

Co-Founder & CTO

Authomize

Mr. Gal Diskin is a cybersecurity and AI researcher. He was previously the VP & head of Palo Alto Networks’ Israeli site, and is a serial entrepreneur. Mr. Diskin’s research has been featured in HITB, Defcon, Black Hat, CCC, and other conferences, spanning fields from low level security research such as hardware vulnerabilities, binary instrumentation, and car hacking to high level research on AI detection methods, Enterprise security, and Identity security. Mr. Diskin was also the technical lead and co-founder of Intel’s software security organization, as well as the CTO of Cyvera and HeXponent (co-founder) before their acquisition.

Senior Security Researcher

Huajiang โ€œKevin2600โ€ Chen (Twitter: @kevin2600) is a senior security researcher. He mainly focuses on vulnerability research in wireless and Vehicle security. He is a winner of GeekPwn 2020 and also made to the Tesla hall of fame 2021. Kevin2600 has spoken at various conferences including KCON; DEFCON and CANSECWEST.

Security Researcher

Li Siwei is a security researcher. He specializes in Big data analysis and AI Security.

Founder, CEO

CloudSEK

Rahul Sasi is an Indian entrepreneur, Founder of CloudSEK, and a security expert. He was voted as the top influential Cyber Security person in 2015, he has made a significant open source contribution to the security landscape and is an invited speaker to over 20+ countries. He is part of the working committees of RBI and MeitY.
CloudSEK : https://cloudsek.com/
LinkedIn: https://www.linkedin.com/in/fb1h2s/

Senior Security Engineer

CloudSEK

Vishal Singh is working as a Senior Security Engineer at CloudSEK. His main responsibility includes handling the Research & Development of CloudSEK ASM. He loves automating manual effort tasks, and also likes net surfing & exploring new places in his free time.

Other Talks in This Track

LOCATION

CommSec Track

DATE

August 26

TIME

16:30

LOCATION

CommSec Track

DATE

August 26

TIME

17:30

LOCATION

CommSec Track

DATE

August 26

TIME

12:00