Sep 2026· Communications of International Proceedings· 0 citations
TL;DR
A proprietary methodology for identifying LOLBin abuse in Windows environments, based on telemetry collected by Sysmon and machine learning models is presented, which indicates that incorporating the context of natural user behavior significantly reduces the number of false alarms and increases the effectiveness of detection for unknown attack variants.
Abstract
Modern advanced cyber attacks increasingly use native operating system tools to hide their presence and bypass security mechanisms. One popular technique is living-off-the-land binaries (LOLBins), which make classic signature-based detection difficult. This article presents a proprietary methodology for identifying LOLBin abuse in Windows environments, based on telemetry collected by Sysmon and machine learning models. The research was conducted in a controlled virtual machine environment, where attack scenarios were carried out using PowerShell commands and selected LOLBins, while generating a realistic user activity profile. The recorded logs were processed, labeled, and analyzed for features, and then used in the training process of classification models such as Random Forest and XGBoost. The results indicate that incorporating the context of natural user behavior significantly reduces the number of false alarms and increases the effectiveness of detection for unknown attack variants. The article discusses the process of creating a test environment, the data processing procedure, the selection of input features, and the results of comparing different algorithms. The limitations of the presented solution and future research directions are also indicated, including the extension of scenarios to other system platforms and integration with SIEM-type tools.
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
Intrusion detection systems based on machine learning achieve high effectiveness under optimal testing conditions. However, real environments come with limitations such as changing data characteristics, previously unknown attacks or low and delayed label availability. To address these challenges, this paper proposed an...
Julia Stępień, I. El Fray· Advances in Science and Tech...· 0 citations
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
Wenxuan Cao· Science and Technology of En...· 0 citations
A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.
Gaurav Kishor Saxena, Shambhu Dayal Sahu· International Journal of Cre...· 0 citations
The healthcare industry has witnessed a significant transformation due to the emergence of open-source medical cyber-physical systems, primarily driven by advancements in 3D printing technology. However, the growing use of these open-source systems in hospitals has also brought about cybersecurity concerns. In particul...
The purpose of this study is to develop an approach for implementing DDoS protection mechanisms in corporate networks using a decision-making system based on machine learning methods. The proposed DDoS attack detection process comprises several stages, including data collection and analysis, model training, feature sel...
A. A. Alekseeva, L. Safiullina, A. M. Sadykov· INFORMACIONNYE TEHNOLOGII· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.