Závěrečná práce: Vardaan Singh: Evading Endpoint Detection and Response Systems through DLL Sideloading Exploitation
Diplomová práce
Získaná ocenění:
Cena děkana FI za vynikající závěrečnou práci
Evading Endpoint Detection and Response Systems through DLL Sideloading Exploitation
Vardaan Singh
Abstract
Endpoint Detection and Response (EDR) systems play a critical role in safeguarding against malicious activities. However, adversaries keep changing their techniques to evade detection. This thesis delves into DLL based attacks, primarily focusing on DLL sideloading as a method to circumvent EDR systems. The study starts with an overview on DLL based attack methodologies concentrating on DLL sideloading …více
Zadání práce
The objective of this master's thesis is to evade Endpoint Detection and Response (EDR) systems by exploiting DLL sideloading. The research will commence with identifying and studying various types of DLL-based attacks. The next phase will involve a comprehensive focus on DLL sideloading attack. Subsequently, the thesis will involve implementing traditional DLL based attack and to identify its weakness. The final phase will involve creating an implementation of DLL sideloading attack that will evade Windows Defender. In addition, the thesis will conclude with a discussion on potential countermeasures that could be employed by EDR systems to mitigate the risks posed by DLL sideloading attacks.
Objectives:
Methodology:
The first segment of this thesis will involve conducting an extensive review of DLL-based attack techniques to establish a foundational understanding. It will further include a focus on DLL sideloading attack. The following segment will include examination of a naive implementation of DLL based attack. The final phase will include crafting a DLL sideloading implementation to evade Windows Defender with a discussion on how to counter its evasion.
Expected Outcomes:
Objectives:
- Conduct a comprehensive review of DLL-based attack methodologies, including DLL sideloading, to understand their relevance to EDR evasion.
- Implement traditional DLL based attack and point out its inefficiencies.
- Develop a customised DLL sideloading implementation specifically designed to evade detection by Windows Defender.
- Suggest countermeasures to the developed sideloading implementation.
Methodology:
The first segment of this thesis will involve conducting an extensive review of DLL-based attack techniques to establish a foundational understanding. It will further include a focus on DLL sideloading attack. The following segment will include examination of a naive implementation of DLL based attack. The final phase will include crafting a DLL sideloading implementation to evade Windows Defender with a discussion on how to counter its evasion.
Expected Outcomes:
- A comprehensive understanding of DLL-based attack techniques with a focus on DLL sideloading.
- Critical analysis of an existing DLL based attack implementation, highlighting its limitations in evading detection.
- Development of a DLL sideloading implementation optimized for evading detection by Windows Defender.
- Suggested countermeasures to the evasion technique used in the sideloading implementation.
Práce zkontrolována:
18. 12. 2024 07:31, prof. RNDr. Václav Matyáš, M.Sc., Ph.D., učo 344
18. 12. 2024 07:31, prof. RNDr. Václav Matyáš, M.Sc., Ph.D., učo 344
Jazyk práce
Termín obhajoby
3. 2. 2025
Práce byla úspěšně obhájena
Studijní program
Plán
Information Security
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Analysis and detection of Skype network traffic
Mgr. Luboš Ptáček -
Analysis and detection of Skype network traffic
Mgr. Luboš Ptáček
Název
Vložil
Vloženo
Práva
Složky
Soubory
19. 1. 2025




