Diplomová práce
Získaná ocenění: Cena děkana FI za vynikající závěrečnou práci

Evading Endpoint Detection and Response Systems through DLL Sideloading Exploitation

Vardaan Singh
Abstract

Endpoint Detection and Response (EDR) systems play a critical role in safeguarding against malicious activities. However, adversaries keep changing their techniques to evade detection. This thesis delves into DLL based attacks, primarily focusing on DLL sideloading as a method to circumvent EDR systems. The study starts with an overview on DLL based attack methodologies concentrating on DLL sideloading …více

Zadání práce
The objective of this master's thesis is to evade Endpoint Detection and Response (EDR) systems by exploiting DLL sideloading. The research will commence with identifying and studying various types of DLL-based attacks. The next phase will involve a comprehensive focus on DLL sideloading attack. Subsequently, the thesis will involve implementing traditional DLL based attack and to identify its weakness. The final phase will involve creating an implementation of DLL sideloading attack that will evade Windows Defender. In addition, the thesis will conclude with a discussion on potential countermeasures that could be employed by EDR systems to mitigate the risks posed by DLL sideloading attacks.

Objectives:
  1. Conduct a comprehensive review of DLL-based attack methodologies, including DLL sideloading, to understand their relevance to EDR evasion.
  2. Implement traditional DLL based attack and point out its inefficiencies.
  3. Develop a customised DLL sideloading implementation specifically designed to evade detection by Windows Defender.
  4. Suggest countermeasures to the developed sideloading implementation.

Methodology:

The first segment of this thesis will involve conducting an extensive review of DLL-based attack techniques to establish a foundational understanding. It will further include a focus on DLL sideloading attack. The following segment will include examination of a naive implementation of DLL based attack. The final phase will include crafting a DLL sideloading implementation to evade Windows Defender with a discussion on how to counter its evasion.

Expected Outcomes:
  1. A comprehensive understanding of DLL-based attack techniques with a focus on DLL sideloading.
  2. Critical analysis of an existing DLL based attack implementation, highlighting its limitations in evading detection.
  3. Development of a DLL sideloading implementation optimized for evading detection by Windows Defender.
  4. Suggested countermeasures to the evasion technique used in the sideloading implementation.
Práce zkontrolována:
18. 12. 2024 07:31, prof. RNDr. Václav Matyáš, M.Sc., Ph.D., učo 344
Plný text práce
4,4 MB / soubor PDF
Jazyk práce
angličtina angličtina
Termín obhajoby
3. 2. 2025
Práce byla úspěšně obhájena

Vedoucí

prof. RNDr. Václav Matyáš, M.Sc., Ph.D., učo 344
KPSK FI MU

Oponent

Mgr. et Mgr. Jan Krhovják, Ph.D., učo 39510
KPSK FI MU

Masarykova univerzita Fakulta informatiky
Plán
Information Security

Práce na příbuzné téma

Seznam prací, které mají shodná klíčová slova.

  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.